ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization is preparing an internal audit of its ISO/IEC 27001-aligned information security management system (ISMS) that covers several IaaS and PaaS workloads hosted in different regions. To help the audit team determine which Annex A controls must be examined, the lead auditor asks for a single document that lists every control, shows whether it is implemented, and explains any exclusions. Which ISMS artefact should you provide?
The Statement of Applicability (SoA) is required by ISO/IEC 27001 clause 6.1.3. It enumerates every Annex A control, notes whether the control is implemented, lists any controls that have been excluded, and justifies those exclusions. Because it maps risk-treatment decisions to specific controls and shows their implementation status, auditors rely on the SoA to define audit scope and verify that the ISMS addresses identified risks.
The risk treatment plan details actions, timelines, and responsible parties for mitigating risks, but it does not necessarily include the full control set or implementation status. An information security policy states management's high-level direction, and an asset inventory register catalogs assets; neither document provides the comprehensive control mapping needed for scoping an internal audit.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Statement of Applicability (SoA) in ISO/IEC 27001?
Open an interactive chat with Bash
What is the purpose of Annex A in ISO/IEC 27001?
Open an interactive chat with Bash
How does the Statement of Applicability differ from a Risk Treatment Plan?
Open an interactive chat with Bash
What is ISO/IEC 27001 and why is it important?
Open an interactive chat with Bash
What is the purpose of the Statement of Applicability (SoA)?
Open an interactive chat with Bash
How does the SoA differ from a risk treatment plan?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .