4. Declaration of applicability
Many standards include annexes. However, NF ISO/IEC 27001 is unique in that its Annex A is normative. This means that, to obtain the certificate, the candidate organization must meet all its requirements.
The documented response to the requirements of Appendix A must be formalized in the Statement of Applicability (SoA). This document describes the security objectives and appropriate measures applicable to the organization's information security management system.
SCROLL TO TOP
You do not have access to this resource.
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed?
Log in!
Ongoing reading
Declaration of applicability