workflow

ISO 27001 SoA Review & Controls Assessment

Review the ISO 27001 Statement of Applicability and assess the controls behind it. Each run attaches to an Audit item created for the review cycle (audit_type = compliance, e.g. "ISO 27001 SoA Review 2026-H2"), which accumulates the scope, the per-control test instances, the assessment package, the approval, and the rating. The workflow locks the assessment workplan, reconciles every Annex A control's applicable/excluded decision and justification against the current risk treatment plan, verifies implementation evidence, assesses the sampled controls for design and operating effectiveness, routes deficiencies to owners, and approves and publishes the version-controlled Statement of Applicability (SoA) — then classifies the disposition and prepares, approves, hands off, and archives the review package. In scope: reconciling and assessing the SoA's Annex A control applicability decisions and their implementation for the ISMS in scope, and publishing the approved SoA version. It consumes the ISMS Risk Assessment & Treatment Cycle's handoff package (the current risk register, the risk treatment decisions, and the required-controls determination) and hands its named deliverable — the approved, version-controlled published SoA and the assessment package — off to the downstream ISO 27001 Certification Readiness workflow. Out of scope: the enterprise risk assessment and treatment decisions that determine which controls are required (owned upstream by the ISMS Risk Assessment & Treatment Cycle) and the certification audit preparation that follows (owned by the downstream ISO 27001 Certification Readiness workflow, which consumes this review's approved package). The trigger is the scheduled SoA review interval or a material change to scope, risk, or the control environment.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
monitor

Details

teams
  • it
  • compliance-legal
domains
  • controls
standards
  • iso-27001
sourceTemplateId
workflow-library:controls-iso27001-soa-review
releaseId
sha256:8131d31962a4d6bfc7156742399d4a2f6ed9ee12af11daec6dfe1648c3a575d8
canonicalUrl
https://workflow-library.com/all/?w=controls-iso27001-soa-review
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-GOV-16
    • UC-AUDIT-21
    • UC-RISK-14
    • UC-GOV-15
    • UC-ACCESS-19
    • UC-ASSET-01
    • UC-ASSET-02
    • UC-ASSET-03
    • UC-ASSET-04
    • UC-ASSET-06
    • UC-ASSET-07
    • UC-ASSET-08
    • UC-ASSET-09
    • UC-GOV-06
    • UC-GOV-07
    • UC-GOV-08
    • UC-HR-01
    • UC-HR-02
    • UC-HR-04
    • UC-HR-05
    • UC-HR-07
    • UC-PHYS-01
    • UC-PHYS-02
    • UC-PHYS-03
    • UC-PHYS-04
    • UC-PHYS-05
    • UC-PHYS-06
    • UC-PHYS-08
    • UC-PHYS-09
    • UC-PHYS-10
    • UC-PHYS-11
    • UC-PHYS-12
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:8131d31962a4d6bfc7156742399d4a2f6ed9ee12af11daec6dfe1648c3a575d8

            Connections