I would like your point of view on the following:
I am confused about how to interpret this clause
If I had an SoA with the following columns, will it meet the requirements of this clause:
or should it be like this to meet the requirement?
To meet this requirement you should consider these fields from your example:
Annex A reference
Justification for inclusion/exclusion (you do not need separated columns because these situations are mutually exclusive)
You should also consider these additional fields:
Control objectives (because security objectives are required by the standard, this field can help you fulfill this requirement in this same document)
Implementation method (this field can help in the understanding of your security environment by providing a short description of controls that do not require a specific document to be written, or by providing a link to a developed document).