Statement of Applicability (SoA)
Standard: ISO/IEC 27001:2022 | Baseline Cross-Reference: Cyber Essentials Plus (CE+)
| Ref | Control Name | Incl. | Justification & CE+ Overlap | Status | Primary Evidence / Artifact |
|---|---|---|---|---|---|
| A.5.1 | Policies for information security | Y | Core ISMS governance requirement. | Implemented | Information Security Policy |
| A.5.9 | Inventory of information & assets | Y | Asset management prerequisite. CE+ HW/SW inventory expanded. | Implemented | Asset Register |
| A.5.12 | Classification of information | Y | Contractual confidentiality & UK GDPR. | Implemented | Data Classification Policy |
| A.5.15 | Access control | Y | Enforce least-privilege. Inherited from CE+ identity controls. | Implemented | Access Control Policy |
| A.5.18 | Access rights | Y | Prevent privilege creep. | In Progress | Quarterly User Entitlement Review Log |
| A.5.19 | Supplier relationship security | Y | Mitigate third-party & SaaS supply-chain risk. | Implemented | Supplier Register |
| A.5.24 | Incident management planning | Y | Operational resilience & breach response. | Implemented | Incident Response Plan |
| A.6.1 | Screening | Y | Pre-employment background verification. | Implemented | HR Pre-Employment Check Records |
| A.6.3 | Security awareness training | Y | Mitigate phishing & social engineering. | In Progress | Phishing Simulation & Training Portal Logs |
| A.6.5 | Responsibilities after termination | Y | Prevent post-employment data leakage. | Implemented | Leaver Procedure |
| A.7.1 | Physical security perimeters | Y | Prevent unauthorized physical premises access. | Implemented | Office Lease Agreement; Fob Access Logs |
| A.7.7 | Clear desk and clear screen | Y | Inherited from CE+ 15-min MDM screen lock. | Implemented | Clean Desk & Clear Screen |
| A.8.1 | User endpoint devices | Y | Inherited from CE+ endpoint audit. | Implemented | Intune Endpoint Compliance Reports |
| A.8.2 | Privileged access rights | Y | Inherited from CE+ admin account separation. | Implemented | Admin Account Directory; MFA Logs |
| A.8.5 | Secure authentication | Y | Inherited from CE+ mandatory MFA baseline. | Implemented | Azure AD Conditional Access Policies |
| A.8.7 | Protection against malware | Y | Inherited from CE+ EDR requirement. | Implemented | Microsoft Defender for Endpoint Console |
| A.8.8 | Technical vulnerability mgmt | Y | Inherited from CE+ 14-day high-risk patch SLA. | Implemented | Automated Patch Management Reports |
| A.8.9 | Configuration management | Y | Inherited from CE+ secure baseline images. | Implemented | Intune Configuration Profiles |
| A.8.13 | Information backup | Y | Business continuity & ransomware defense. | Implemented | Immutable Cloud Backup Logs & Restore Tests |
| A.8.15 | Logging | Y | Forensic analysis & security monitoring. | In Progress | Central SIEM / Cloud Audit Retention |
| A.8.20 | Network security | Y | Inherited from CE+ boundary firewall audit. | Implemented | Next-Gen Firewall Configuration Rules |
| A.8.24 | Use of cryptography | Y | Inherited from CE+ BitLocker/TLS requirements. | Implemented | BitLocker Enforcement Dashboard |