workflow
ISO 27001 SoA Review & Controls Assessment
Review the ISO 27001 Statement of Applicability and assess the controls behind it. Each run attaches to an Audit item created for the review cycle (audit_type = compliance, e.g. "ISO 27001 SoA Review 2026-H2"), which accumulates the scope, the per-control test instances, the assessment package, the approval, and the rating. The workflow locks the assessment workplan, reconciles every Annex A control's applicable/excluded decision and justification against the current risk treatment plan, verifies implementation evidence, assesses the sampled controls for design and operating effectiveness, routes deficiencies to owners, and approves and publishes the version-controlled Statement of Applicability (SoA) — then classifies the disposition and prepares, approves, hands off, and archives the review package. In scope: reconciling and assessing the SoA's Annex A control applicability decisions and their implementation for the ISMS in scope, and publishing the approved SoA version. It consumes the ISMS Risk Assessment & Treatment Cycle's handoff package (the current risk register, the risk treatment decisions, and the required-controls determination) and hands its named deliverable — the approved, version-controlled published SoA and the assessment package — off to the downstream ISO 27001 Certification Readiness workflow. Out of scope: the enterprise risk assessment and treatment decisions that determine which controls are required (owned upstream by the ISMS Risk Assessment & Treatment Cycle) and the certification audit preparation that follows (owned by the downstream ISO 27001 Certification Readiness workflow, which consumes this review's approved package). The trigger is the scheduled SoA review interval or a material change to scope, risk, or the control environment.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- monitor
Details
- teams
- it
- compliance-legal
- domains
- controls
- standards
- iso-27001
- sourceTemplateId
- workflow-library:controls-iso27001-soa-review
- releaseId
- sha256:8131d31962a4d6bfc7156742399d4a2f6ed9ee12af11daec6dfe1648c3a575d8
- canonicalUrl
- https://workflow-library.com/all/?w=controls-iso27001-soa-review
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-GOV-16
- UC-AUDIT-21
- UC-RISK-14
- UC-GOV-15
- UC-ACCESS-19
- UC-ASSET-01
- UC-ASSET-02
- UC-ASSET-03
- UC-ASSET-04
- UC-ASSET-06
- UC-ASSET-07
- UC-ASSET-08
- UC-ASSET-09
- UC-GOV-06
- UC-GOV-07
- UC-GOV-08
- UC-HR-01
- UC-HR-02
- UC-HR-04
- UC-HR-05
- UC-HR-07
- UC-PHYS-01
- UC-PHYS-02
- UC-PHYS-03
- UC-PHYS-04
- UC-PHYS-05
- UC-PHYS-06
- UC-PHYS-08
- UC-PHYS-09
- UC-PHYS-10
- UC-PHYS-11
- UC-PHYS-12
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:8131d31962a4d6bfc7156742399d4a2f6ed9ee12af11daec6dfe1648c3a575d8
Connections
- ISO 27001 SoA Review & Controls Assessment oversees UC-HR-02 — Formalize security responsibilities in employment terms
- ISO 27001 SoA Review & Controls Assessment oversees UC-ASSET-04 — Control storage media through use, storage, and destruction
- ISO 27001 SoA Review & Controls Assessment oversees UC-HR-05 — Hold third-party personnel to equivalent security terms
- ISO 27001 SoA Review & Controls Assessment oversees UC-GOV-15 — Operate a management-approved information security program
- ISO 27001 SoA Review & Controls Assessment oversees UC-PHYS-12 — Mark hardware components with handling designations
- ISO 27001 SoA Review & Controls Assessment oversees UC-PHYS-11 — Secure alternate work sites
- ISO 27001 SoA Review & Controls Assessment oversees UC-GOV-16 — Select and tailor a risk-based control baseline
- ISO 27001 SoA Review & Controls Assessment oversees UC-ASSET-07 — Manage assets through their life cycle and recover them at exit
- ISO 27001 SoA Review & Controls Assessment oversees UC-PHYS-01 — Restrict physical access to facilities and secure areas
- ISO 27001 SoA Review & Controls Assessment oversees UC-ASSET-08 — Transfer information securely under defined rules and agreements
- ISO 27001 SoA Review & Controls Assessment oversees UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
- ISO 27001 SoA Review & Controls Assessment oversees UC-PHYS-08 — Maintain equipment to preserve availability and integrity
- ISO 27001 SoA Review & Controls Assessment oversees UC-PHYS-03 — Protect facilities against fire, water, and environmental hazards
- ISO 27001 SoA Review & Controls Assessment oversees UC-PHYS-09 — Prevent information exposure at desks, screens, and outputs
- ISO 27001 SoA Review & Controls Assessment oversees UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems
- ISO 27001 SoA Review & Controls Assessment oversees UC-GOV-08 — Segregate conflicting duties and areas of responsibility
- ISO 27001 SoA Review & Controls Assessment oversees UC-HR-04 — Enforce a formal disciplinary process for violations
- ISO 27001 SoA Review & Controls Assessment oversees UC-HR-01 — Screen personnel commensurate with position risk
- ISO 27001 SoA Review & Controls Assessment oversees UC-ASSET-03 — Classify, prioritize, and label information and assets
- ISO 27001 SoA Review & Controls Assessment oversees UC-GOV-06 — Define security roles, responsibilities, and authorities
- ISO 27001 SoA Review & Controls Assessment oversees UC-RISK-14 — Track deficiencies to closure with remediation action plans
- ISO 27001 SoA Review & Controls Assessment oversees UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards
- ISO 27001 SoA Review & Controls Assessment oversees UC-ASSET-09 — Receive, analyze, and act on threat and vulnerability intelligence
- ISO 27001 SoA Review & Controls Assessment oversees UC-PHYS-05 — Provide emergency power, lighting, and resilient utilities
- ISO 27001 SoA Review & Controls Assessment oversees UC-PHYS-10 — Control and track asset delivery, removal, and movement
- ISO 27001 SoA Review & Controls Assessment oversees UC-PHYS-04 — Site facilities and equipment to minimize hazards and exposure
- ISO 27001 SoA Review & Controls Assessment oversees UC-HR-07 — Secure remote working arrangements
- ISO 27001 SoA Review & Controls Assessment oversees UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software
- ISO 27001 SoA Review & Controls Assessment oversees UC-PHYS-02 — Monitor physical access and retain visitor and entry records
- ISO 27001 SoA Review & Controls Assessment oversees UC-ASSET-02 — Inventory data and document processing activities and flows
- ISO 27001 SoA Review & Controls Assessment oversees UC-PHYS-06 — Protect power and communications cabling from damage and taps
- ISO 27001 SoA Review & Controls Assessment oversees UC-GOV-07 — Hold individuals accountable for control responsibilities