SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Statement Of Applicability

  Quote
Frank Van Heyghen Created:   Jun 09, 2020 Last commented:   Jun 10, 2020

Statement Of Applicability

Is there a rule of thumb (or best practice) as to how many controls from Annex A need to be sustained in the SOA (for smaller companies, i.e. 50-100 employees)?

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jun 10, 2020

From our experience with our customers, smaller companies are usually at ca 100 controls, while larger ones are usually above 110.

But please note that the main criteria considered by certification bodies to justify controls applicability are results of risk assessment and applicable legal requirements (e.g., laws, regulations, and contracts).

It is important to understand that because you can have similar organizations with totality different quantity of applicable controls (above or below the mentioned numbers), because they have different approaches towards risks (e.g., more risk aggressive, more cautious, etc.), and still both can fulfill the standards criteria for certification.

For further information, see:

This material can also help you:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jun 09, 2020

Jun 10, 2020