Skip to content

Statement of Applicability (SoA)

Standard: ISO/IEC 27001:2022 | Baseline Cross-Reference: Cyber Essentials Plus (CE+)

Ref Control Name Incl. Justification & CE+ Overlap Status Primary Evidence / Artifact
A.5.1 Policies for information security Y Core ISMS governance requirement. Implemented Information Security Policy
A.5.9 Inventory of information & assets Y Asset management prerequisite. CE+ HW/SW inventory expanded. Implemented Asset Register
A.5.12 Classification of information Y Contractual confidentiality & UK GDPR. Implemented Data Classification Policy
A.5.15 Access control Y Enforce least-privilege. Inherited from CE+ identity controls. Implemented Access Control Policy
A.5.18 Access rights Y Prevent privilege creep. In Progress Quarterly User Entitlement Review Log
A.5.19 Supplier relationship security Y Mitigate third-party & SaaS supply-chain risk. Implemented Supplier Register
A.5.24 Incident management planning Y Operational resilience & breach response. Implemented Incident Response Plan
A.6.1 Screening Y Pre-employment background verification. Implemented HR Pre-Employment Check Records
A.6.3 Security awareness training Y Mitigate phishing & social engineering. In Progress Phishing Simulation & Training Portal Logs
A.6.5 Responsibilities after termination Y Prevent post-employment data leakage. Implemented Leaver Procedure
A.7.1 Physical security perimeters Y Prevent unauthorized physical premises access. Implemented Office Lease Agreement; Fob Access Logs
A.7.7 Clear desk and clear screen Y Inherited from CE+ 15-min MDM screen lock. Implemented Clean Desk & Clear Screen
A.8.1 User endpoint devices Y Inherited from CE+ endpoint audit. Implemented Intune Endpoint Compliance Reports
A.8.2 Privileged access rights Y Inherited from CE+ admin account separation. Implemented Admin Account Directory; MFA Logs
A.8.5 Secure authentication Y Inherited from CE+ mandatory MFA baseline. Implemented Azure AD Conditional Access Policies
A.8.7 Protection against malware Y Inherited from CE+ EDR requirement. Implemented Microsoft Defender for Endpoint Console
A.8.8 Technical vulnerability mgmt Y Inherited from CE+ 14-day high-risk patch SLA. Implemented Automated Patch Management Reports
A.8.9 Configuration management Y Inherited from CE+ secure baseline images. Implemented Intune Configuration Profiles
A.8.13 Information backup Y Business continuity & ransomware defense. Implemented Immutable Cloud Backup Logs & Restore Tests
A.8.15 Logging Y Forensic analysis & security monitoring. In Progress Central SIEM / Cloud Audit Retention
A.8.20 Network security Y Inherited from CE+ boundary firewall audit. Implemented Next-Gen Firewall Configuration Rules
A.8.24 Use of cryptography Y Inherited from CE+ BitLocker/TLS requirements. Implemented BitLocker Enforcement Dashboard