{"id":24448,"date":"2026-05-15T14:50:57","date_gmt":"2026-05-15T12:50:57","guid":{"rendered":"https:\/\/instant27001.com\/?p=24448"},"modified":"2026-05-21T15:22:19","modified_gmt":"2026-05-21T13:22:19","slug":"statement-of-applicability-iso-27001","status":"publish","type":"post","link":"https:\/\/instant27001.com\/sv\/statement-of-applicability-iso-27001\/","title":{"rendered":"Everything you need to know about the Statement of Applicability (SoA) for ISO 27001"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The Statement of Applicability (SoA) is often described as the heartbeat of your Information Security Management System (ISMS). While the risk assessment identifies the &#8217;why&#8217;, the SoA defines the &#8217;what&#8217; and the &#8217;how&#8217;. It is the single most important document during your certification audit and the definitive roadmap for your internal security operations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At Instant 27001, we believe compliance shouldn&#8217;t be a manual burden. We help you move from static, error-prone spreadsheets to a dynamic, automated SoA that evolves with your business.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-fe48e5de wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button is-style-outline is-style-outline--1\"><a class=\"wp-block-button__link has-white-color has-text-color has-background has-link-color has-custom-font-size wp-element-button\" href=\"https:\/\/instant27001.com\/order\/\" style=\"border-top-left-radius:24px;border-top-right-radius:24px;border-bottom-left-radius:24px;border-bottom-right-radius:24px;background-color:#ef767a;font-size:18px\"><strong>Order now<\/strong><\/a><\/div>\n\n\n\n<div class=\"wp-block-button is-style-outline is-style-outline--2\"><a class=\"wp-block-button__link has-white-color has-text-color has-background has-link-color has-custom-font-size wp-element-button\" href=\"https:\/\/instant27001.com\/book-a-demo\/\" style=\"border-top-left-radius:24px;border-top-right-radius:24px;border-bottom-left-radius:24px;border-bottom-right-radius:24px;background-color:#00aeef;font-size:18px\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Book a demo<\/strong><\/a><\/div>\n<\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Why the SoA is non-negotiable<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A common misconception is that the SoA is merely a checkbox for the auditor. In reality, a well-crafted SoA acts as a strategic filter for your organisation:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Risk mitigation mastery: <\/strong>it ensures that every significant risk identified in your assessment has a corresponding defensive measure.<\/li>\n\n\n\n<li><strong>Resource optimisation: <\/strong>by justifying exclusions, you prevent &#8221;security bloat&#8221;: the practice of implementing costly controls that provide no actual value to your specific business model.<\/li>\n\n\n\n<li><strong>Stakeholder transparency:<\/strong> in an era of supply-chain attacks, your SoA is your &#8221;Security Passport&#8221;. It provides a granular level of detail that a simple certificate cannot, proving to high-value clients exactly how you protect their intellectual property.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Who is the SoA for? (And who demands it?)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you are pursuing ISO 27001 certification, the SoA isn&#8217;t optional. It&#8217;s the core requirement. But its utility extends far beyond the compliance department:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Fast-growth SaaS &amp; tech teams:<\/strong> to prove to enterprise clients that your &#8221;secure-by-design&#8221; claims are backed by specific, documented Annex A controls.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Compliance &amp; security officers:<\/strong> to create a central &#8221;Source of Truth&#8221; that prevents internal confusion and ensures every department knows its security obligations.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>External auditors:<\/strong> this is the first document they touch. A precise SoA sets the tone for a smooth, successful audit.<br \/><\/li>\n\n\n\n<li><strong>Stakeholders &amp; board members: <\/strong>to provide a high-level yet verifiable overview of the company\u2019s risk posture and investment in security infrastructure.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Deep dive into the ISO 27001:2022 structure<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the 2022 update, ISO 27001 underwent a massive architectural shift. The standard moved away from the fragmented 14-domain structure of the past, consolidating 114 controls down to 93 modern security measures. These controls are now organized into four logical themes. This restructuring isn&#8217;t just about brevity; it\u2019s about aligning information security with the way modern, cloud-first businesses actually operate.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Organizational controls (37 controls)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The definition<\/strong><br \/>Organizational controls serve as the &#8221;Operating System&#8221; of your ISMS. They define the high-level logic, governance frameworks, and operational protocols that dictate how your entire company approaches security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The shift<\/strong><br \/>ISO moved away from scattered compliance requirements to a unified governance model. By merging previously separate domains like &#8221;Supplier Security&#8221; and &#8221;Security Organization,&#8221; the standard now aligns directly with global risk management methodologies like ISO 31000.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The business advantage<\/strong><br \/>This pillar eliminates &#8221;policy overlap,&#8221; reducing administrative bloat. For leadership, it provides a single, coherent framework for decision-making, ensuring that security is a boardroom priority rather than an IT-only concern.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Critical controls to watch:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A.5.7 \u2013 Threat Intelligence (New): Moves you from reactive defense to proactive hunting by analyzing external threat data.<\/li>\n\n\n\n<li>A.5.23 \u2013 Cloud Services Security: Specifically addresses the &#8221;Shared Responsibility Model&#8221; for SaaS and cloud-native environments.<\/li>\n\n\n\n<li>A.5.31 \u2013 Legal &amp; Regulatory Compliance: A consolidated &#8221;master control&#8221; for managing GDPR, CCPA, and contractual obligations.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u00a02. People controls (8 controls)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The definition<\/strong><br \/>Organizational controls serve as the &#8221;Operating System&#8221; of your ISMS. They define the high-level logic, governance frameworks, and operational protocols that dictate how your entire company approaches security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The shift<\/strong><br \/>ISO moved away from scattered compliance requirements to a unified governance model. By merging previously separate domains like &#8221;Supplier Security&#8221; and &#8221;Security Organization,&#8221; the standard now aligns directly with global risk management methodologies like ISO 31000.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The business advantage<\/strong><br \/>This pillar eliminates &#8221;policy overlap,&#8221; reducing administrative bloat. For leadership, it provides a single, coherent framework for decision-making, ensuring that security is a boardroom priority rather than an IT-only concern.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Critical controls to watch:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A.5.7 \u2013 Threat Intelligence (New): Moves you from reactive defense to proactive hunting by analyzing external threat data.<\/li>\n\n\n\n<li>A.5.23 \u2013 Cloud Services Security: Specifically addresses the &#8221;Shared Responsibility Model&#8221; for SaaS and cloud-native environments.<\/li>\n\n\n\n<li>A.5.31 \u2013 Legal &amp; Regulatory Compliance: A consolidated &#8221;master control&#8221; for managing GDPR, CCPA, and contractual obligations.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">3. Physical controls (14 controls)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The definition<\/strong><br \/>Physical controls protect the tangible assets like, facilities, hardware, and infrastructure, that house your digital data. This includes everything from office entry points to the security of home-office workstations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The shift<\/strong><br \/>This pillar has been modernized for the Hybrid Work Era. It acknowledges that the &#8221;office&#8221; is no longer a single building, but a distributed network of home offices, coworking spaces, and data centers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The business advantage<\/strong><br \/>By securing the &#8221;Physical-Digital&#8221; intersection, you ensure that high-value intellectual property is protected regardless of where your team is working. It provides a standardized framework for managing the risks of a borderless workforce.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Critical controls to watch:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A.7.5 \u2013 Secure Remote Working: The definitive standard for securing a hybrid workforce and preventing data leaks from home offices.<\/li>\n\n\n\n<li>A.7.4 \u2013 Physical Security Monitoring: Moves beyond passive locks to active, real-time intrusion detection and surveillance.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4. Technological controls (34 controls)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The definition<\/strong><br \/>Technological controls are the digital &#8221;locks and keys&#8221; of your infrastructure. This pillar focuses on technical implementations like encryption, network security, and secure software development.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The shift<\/strong><br \/>The 2022 update introduces &#8221;Privacy by Design.&#8221; It adds technical mandates for data masking and leakage prevention that didn&#8217;t exist in the 2013 version, aligning the standard with modern cyber threats like ransomware and SaaS exploits.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The business advantage<\/strong><br \/>For tech companies, this pillar is the ultimate &#8221;Trust Builder.&#8221; It proves to your clients that your software is built securely (Secure Coding) and that their sensitive data is technically shielded from unauthorized access or accidental transfer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Critical controls to watch:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A.8.9 \u2013 Configuration Management: directly addresses the leading cause of cloud breaches: human misconfiguration.<\/li>\n\n\n\n<li>A.8.12 \u2013 Data Leakage Prevention (DLP): technical safeguards to ensure sensitive data never leaves your controlled environment.<\/li>\n\n\n\n<li>A.8.28 \u2013 Secure Coding: essential for software companies to ensure security is baked into the development lifecycle from day one.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Why managing controls with Instant 27001 matters\u00a0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Manually mapping these 93 controls to your specific risks is a recipe for error. Instant 27001 automates this mapping, providing you with a pre-configured framework where these controls are already translated into actionable tasks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ready to see the 93 controls in action?<\/p>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-fe48e5de wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button is-style-outline is-style-outline--3\"><a class=\"wp-block-button__link has-white-color has-text-color has-background has-link-color has-custom-font-size wp-element-button\" href=\"https:\/\/instant27001.com\/order\/\" style=\"border-top-left-radius:24px;border-top-right-radius:24px;border-bottom-left-radius:24px;border-bottom-right-radius:24px;background-color:#ef767a;font-size:18px\"><strong>Order now<\/strong><\/a><\/div>\n\n\n\n<div class=\"wp-block-button is-style-outline is-style-outline--4\"><a class=\"wp-block-button__link has-white-color has-text-color has-background has-link-color has-custom-font-size wp-element-button\" href=\"https:\/\/instant27001.com\/book-a-demo\/\" style=\"border-top-left-radius:24px;border-top-right-radius:24px;border-bottom-left-radius:24px;border-bottom-right-radius:24px;background-color:#00aeef;font-size:18px\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Book a demo<\/strong><\/a><\/div>\n<\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">The strategic divide: SoA vs. Risk Assessment report<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">One of the most frequent points of confusion in ISO 27001 is the difference between these two documents. While they are inextricably linked, they serve fundamentally different purposes.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><th>Feature<\/th><th>Risk Assessment Report (RAR)<\/th><th>Risk Assessment Report (RAR)<\/th><\/tr><\/thead><tbody><tr><td><strong>Primary goal<\/strong><\/td><td>To identify vulnerabilities and threats to your information assets.<\/td><td>To declare which security controls are in place to mitigate those risks.<\/td><\/tr><tr><td><strong>Focus<\/strong><\/td><td>&#8221;The problem&#8221;: what could go wrong?<\/td><td>&#8221;The solution&#8221;: what are we doing about it?<\/td><\/tr><tr><td><strong>Content<\/strong><\/td><td>A list of assets, threats, vulnerabilities, and their impact\/likelihood levels.<\/td><td>A definitive list of the 93 Annex A controls with justifications for each.<\/td><\/tr><tr><td><strong>Audience<\/strong><\/td><td>Primarily internal (risk owners and management).<\/td><td>Both internal and external (auditors, partners, and clients).<\/td><\/tr><tr><td><strong>The relationship<\/strong><\/td><td>The RAR provides the input for the SoA.<\/td><td>The SoA provides the output of your security decisions.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Important note:<\/strong> you cannot have a compliant SoA without a thorough Risk Assessment, and you haven&#8217;t &#8221;treated&#8221; your risks until they are mapped in the SoA.<br \/><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">The SoA cycle: 4 steps to audit success asked questions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A &#8221;Solid SoA&#8221; is not a static document; it is the result of a rigorous, repeatable process.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong><\/strong><strong><\/strong><strong>Step 1: the risk-control calibration<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You don&#8217;t select controls because they sound good; you select them because they solve a problem. Every &#8221;Applicable&#8221; control in your SoA should have a direct lineage back to a risk identified in your assessment.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong><\/strong><strong><\/strong><strong><\/strong><strong>Step 2: the strictness of justification<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Inclusion:<\/strong> you must state why a control is selected (e.g., &#8221;Required to mitigate the risk of unauthorised data access&#8221; or &#8221;Contractual requirement for Client X&#8221;).<\/li>\n\n\n\n<li><strong>Exclusion:<\/strong> this is where auditors focus. A vague &#8221;Not applicable&#8221; will trigger a non-conformity. A strong justification explains why the risk doesn&#8217;t exist (e.g., &#8221;No physical office; all operations are 100% remote\/cloud-based&#8221;).<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong><\/strong><strong><\/strong><strong><\/strong><strong><\/strong><strong>Step 3: the reality check (implementation status)<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">ISO 27001 doesn&#8217;t require you to be perfect from day one, but it does require honesty. We categorise controls as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Implemented: <\/strong>evidence is ready for inspection.<\/li>\n\n\n\n<li><strong>Planned:<\/strong> a timeline and owner are assigned.<\/li>\n\n\n\n<li><strong>Partially implemented: <\/strong>progress is documented.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong><\/strong><strong><\/strong><strong><\/strong><strong><\/strong><strong><\/strong><strong>Step 4: the cross-reference check<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Before finalising, you must cross-reference your selection against the full Annex A list. This &#8221;sanity check&#8221; ensures that in your focus on specific risks, you haven&#8217;t missed a foundational security requirement.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">How Instant 27001 reduces the complexity<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The manual era of ISO 27001 is over. Instant 27001 provides a high-velocity environment to manage your SoA:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Dynamic mapping:<\/strong> our engine links risks to controls automatically. When your risk landscape shifts, the platform prompts you to update your SoA, ensuring you never fall out of compliance.<\/li>\n\n\n\n<li><strong>Justification library: <\/strong>stop staring at a blank screen. Access hundreds of expert-written justifications that have already passed dozens of audits in various sectors (SaaS, FinTech, Healthcare).<\/li>\n\n\n\n<li><strong>Version control &amp; audit history: <\/strong>every change is logged. When an auditor asks for the history of your SoA, you can provide a complete, timestamped report with one click.<\/li>\n\n\n\n<li><strong>ISO 27001:2022 native: <\/strong>built from the ground up for the latest standard. We handle the &#8221;mapping headache&#8221; so you can focus on actual security.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-dots\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently asked questions<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Can we have a &#8221;generic&#8221; SoA for the whole group?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">While you can share a template, each legal entity or specific scope usually needs its own SoA to reflect its unique risk environment and local regulations.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What happens if we miss a control in the SoA?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">During an audit, this is usually classified as a major non-conformity. The SoA defines the scope of the certificate; missing a control means the ISMS certificate is fundamentally flawed.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How do we handle &#8221;new&#8221; controls in the 2022 update?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Instant 27001 provides specific guidance for the 11 new controls (like data leakage prevention and monitoring activities), helping you determine if they apply to your current stack.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-fe48e5de wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button is-style-outline is-style-outline--5\"><a class=\"wp-block-button__link has-white-color has-text-color has-background has-link-color has-custom-font-size wp-element-button\" href=\"https:\/\/instant27001.com\/order\/\" style=\"border-top-left-radius:24px;border-top-right-radius:24px;border-bottom-left-radius:24px;border-bottom-right-radius:24px;background-color:#ef767a;font-size:18px\"><strong>Order now<\/strong><\/a><\/div>\n\n\n\n<div class=\"wp-block-button is-style-outline is-style-outline--6\"><a class=\"wp-block-button__link has-white-color has-text-color has-background has-link-color has-custom-font-size wp-element-button\" href=\"https:\/\/instant27001.com\/book-a-demo\/\" style=\"border-top-left-radius:24px;border-top-right-radius:24px;border-bottom-left-radius:24px;border-bottom-right-radius:24px;background-color:#00aeef;font-size:18px\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Book a demo<\/strong><\/a><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Statement of Applicability (SoA) is often described as the heartbeat of your Information Security Management System (ISMS). While the risk assessment identifies the &#8217;why&#8217;, the SoA defines the &#8217;what&#8217; and the &#8217;how&#8217;. It is the single most important document during your certification audit and the definitive roadmap for your internal security operations. At Instant [&hellip;]<\/p>\n","protected":false},"author":23147258,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[1],"tags":[],"class_list":["post-24448","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>All about the Statement of Applicability ISO 27001<\/title>\n<meta name=\"description\" content=\"Get a deep dive into the Statement of Applicability for ISO 27001. Master the 93 controls and set up an audit-ready SoA. Read more.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/instant27001.com\/sv\/statement-of-applicability-iso-27001\/\" \/>\n<meta property=\"og:locale\" content=\"sv_SE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"All about the Statement of Applicability ISO 27001\" \/>\n<meta property=\"og:description\" content=\"Get a deep dive into the Statement of Applicability for ISO 27001. Master the 93 controls and set up an audit-ready SoA. Read more.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/instant27001.com\/sv\/statement-of-applicability-iso-27001\/\" \/>\n<meta property=\"og:site_name\" content=\"Instant 27001\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-15T12:50:57+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-21T13:22:19+00:00\" \/>\n<meta name=\"author\" content=\"jamievanderheiden\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Skriven av\" \/>\n\t<meta name=\"twitter:data1\" content=\"jamievanderheiden\" \/>\n\t<meta name=\"twitter:label2\" content=\"Ber\u00e4knad l\u00e4stid\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minuter\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/statement-of-applicability-iso-27001\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/statement-of-applicability-iso-27001\\\/\"},\"author\":{\"name\":\"jamievanderheiden\",\"@id\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/#\\\/schema\\\/person\\\/6f01d8364769885daf37bb5394879524\"},\"headline\":\"Everything you need to know about the Statement of Applicability (SoA) for ISO 27001\",\"datePublished\":\"2026-05-15T12:50:57+00:00\",\"dateModified\":\"2026-05-21T13:22:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/statement-of-applicability-iso-27001\\\/\"},\"wordCount\":1667,\"publisher\":{\"@id\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/#organization\"},\"articleSection\":[\"Uncategorized\"],\"inLanguage\":\"sv-SE\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/statement-of-applicability-iso-27001\\\/\",\"url\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/statement-of-applicability-iso-27001\\\/\",\"name\":\"All about the Statement of Applicability ISO 27001\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/#website\"},\"datePublished\":\"2026-05-15T12:50:57+00:00\",\"dateModified\":\"2026-05-21T13:22:19+00:00\",\"description\":\"Get a deep dive into the Statement of Applicability for ISO 27001. Master the 93 controls and set up an audit-ready SoA. Read more.\",\"inLanguage\":\"sv-SE\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/instant27001.com\\\/sv\\\/statement-of-applicability-iso-27001\\\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/#website\",\"url\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/\",\"name\":\"Instant 27001\",\"description\":\"Ready-to-run ISMS for ISO 27001\",\"publisher\":{\"@id\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/#organization\"},\"alternateName\":\"DIY ISMS for ISO 27001\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"sv-SE\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/#organization\",\"name\":\"Instant Management Systems B.V.\",\"alternateName\":\"IMS\",\"url\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"sv-SE\",\"@id\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/instant27001.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/IMS-logo-rgb-400.png?fit=400%2C123&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/instant27001.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/IMS-logo-rgb-400.png?fit=400%2C123&ssl=1\",\"width\":400,\"height\":123,\"caption\":\"Instant Management Systems B.V.\"},\"image\":{\"@id\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/instant27001\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/#\\\/schema\\\/person\\\/6f01d8364769885daf37bb5394879524\",\"name\":\"jamievanderheiden\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"sv-SE\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f259271498737aba59ccd09952e3ced472aa4e53a980c035f75f5ed5a29a4a04?s=96&d=retro&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f259271498737aba59ccd09952e3ced472aa4e53a980c035f75f5ed5a29a4a04?s=96&d=retro&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f259271498737aba59ccd09952e3ced472aa4e53a980c035f75f5ed5a29a4a04?s=96&d=retro&r=g\",\"caption\":\"jamievanderheiden\"},\"url\":\"https:\\\/\\\/instant27001.com\\\/sv\\\/author\\\/jamievanderheiden\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"All about the Statement of Applicability ISO 27001","description":"Get a deep dive into the Statement of Applicability for ISO 27001. Master the 93 controls and set up an audit-ready SoA. Read more.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/instant27001.com\/sv\/statement-of-applicability-iso-27001\/","og_locale":"sv_SE","og_type":"article","og_title":"All about the Statement of Applicability ISO 27001","og_description":"Get a deep dive into the Statement of Applicability for ISO 27001. Master the 93 controls and set up an audit-ready SoA. Read more.","og_url":"https:\/\/instant27001.com\/sv\/statement-of-applicability-iso-27001\/","og_site_name":"Instant 27001","article_published_time":"2026-05-15T12:50:57+00:00","article_modified_time":"2026-05-21T13:22:19+00:00","author":"jamievanderheiden","twitter_card":"summary_large_image","twitter_misc":{"Skriven av":"jamievanderheiden","Ber\u00e4knad l\u00e4stid":"8 minuter"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/instant27001.com\/sv\/statement-of-applicability-iso-27001\/#article","isPartOf":{"@id":"https:\/\/instant27001.com\/sv\/statement-of-applicability-iso-27001\/"},"author":{"name":"jamievanderheiden","@id":"https:\/\/instant27001.com\/sv\/#\/schema\/person\/6f01d8364769885daf37bb5394879524"},"headline":"Everything you need to know about the Statement of Applicability (SoA) for ISO 27001","datePublished":"2026-05-15T12:50:57+00:00","dateModified":"2026-05-21T13:22:19+00:00","mainEntityOfPage":{"@id":"https:\/\/instant27001.com\/sv\/statement-of-applicability-iso-27001\/"},"wordCount":1667,"publisher":{"@id":"https:\/\/instant27001.com\/sv\/#organization"},"articleSection":["Uncategorized"],"inLanguage":"sv-SE"},{"@type":"WebPage","@id":"https:\/\/instant27001.com\/sv\/statement-of-applicability-iso-27001\/","url":"https:\/\/instant27001.com\/sv\/statement-of-applicability-iso-27001\/","name":"All about the Statement of Applicability ISO 27001","isPartOf":{"@id":"https:\/\/instant27001.com\/sv\/#website"},"datePublished":"2026-05-15T12:50:57+00:00","dateModified":"2026-05-21T13:22:19+00:00","description":"Get a deep dive into the Statement of Applicability for ISO 27001. Master the 93 controls and set up an audit-ready SoA. Read more.","inLanguage":"sv-SE","potentialAction":[{"@type":"ReadAction","target":["https:\/\/instant27001.com\/sv\/statement-of-applicability-iso-27001\/"]}]},{"@type":"WebSite","@id":"https:\/\/instant27001.com\/sv\/#website","url":"https:\/\/instant27001.com\/sv\/","name":"Instant 27001","description":"Ready-to-run ISMS for ISO 27001","publisher":{"@id":"https:\/\/instant27001.com\/sv\/#organization"},"alternateName":"DIY ISMS for ISO 27001","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/instant27001.com\/sv\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"sv-SE"},{"@type":"Organization","@id":"https:\/\/instant27001.com\/sv\/#organization","name":"Instant Management Systems B.V.","alternateName":"IMS","url":"https:\/\/instant27001.com\/sv\/","logo":{"@type":"ImageObject","inLanguage":"sv-SE","@id":"https:\/\/instant27001.com\/sv\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/instant27001.com\/wp-content\/uploads\/2023\/08\/IMS-logo-rgb-400.png?fit=400%2C123&ssl=1","contentUrl":"https:\/\/i0.wp.com\/instant27001.com\/wp-content\/uploads\/2023\/08\/IMS-logo-rgb-400.png?fit=400%2C123&ssl=1","width":400,"height":123,"caption":"Instant Management Systems B.V."},"image":{"@id":"https:\/\/instant27001.com\/sv\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/instant27001\/"]},{"@type":"Person","@id":"https:\/\/instant27001.com\/sv\/#\/schema\/person\/6f01d8364769885daf37bb5394879524","name":"jamievanderheiden","image":{"@type":"ImageObject","inLanguage":"sv-SE","@id":"https:\/\/secure.gravatar.com\/avatar\/f259271498737aba59ccd09952e3ced472aa4e53a980c035f75f5ed5a29a4a04?s=96&d=retro&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f259271498737aba59ccd09952e3ced472aa4e53a980c035f75f5ed5a29a4a04?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f259271498737aba59ccd09952e3ced472aa4e53a980c035f75f5ed5a29a4a04?s=96&d=retro&r=g","caption":"jamievanderheiden"},"url":"https:\/\/instant27001.com\/sv\/author\/jamievanderheiden\/"}]}},"jetpack_likes_enabled":false,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9910Y-6mk","jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/instant27001.com\/sv\/wp-json\/wp\/v2\/posts\/24448","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/instant27001.com\/sv\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/instant27001.com\/sv\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/instant27001.com\/sv\/wp-json\/wp\/v2\/users\/23147258"}],"replies":[{"embeddable":true,"href":"https:\/\/instant27001.com\/sv\/wp-json\/wp\/v2\/comments?post=24448"}],"version-history":[{"count":35,"href":"https:\/\/instant27001.com\/sv\/wp-json\/wp\/v2\/posts\/24448\/revisions"}],"predecessor-version":[{"id":24690,"href":"https:\/\/instant27001.com\/sv\/wp-json\/wp\/v2\/posts\/24448\/revisions\/24690"}],"wp:attachment":[{"href":"https:\/\/instant27001.com\/sv\/wp-json\/wp\/v2\/media?parent=24448"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/instant27001.com\/sv\/wp-json\/wp\/v2\/categories?post=24448"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/instant27001.com\/sv\/wp-json\/wp\/v2\/tags?post=24448"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}