soa

Assemble an ISO 27001:2022 Statement of Applicability with all 93 Annex A controls.

Updated Apr 28, 2026
One-click install
npx skills add https://github.com/gombing/ISO27001Agent --skill soa
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: soa
Source: https://github.com/gombing/ISO27001Agent/tree/main/soa
Command: npx skills add https://github.com/gombing/ISO27001Agent --skill soa

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The SoA skill streamlines the creation of a formal Statement of Applicability by consolidating risk-treatment decisions and Annex A reviews into a complete, auditable document. It prevents gaps by enforcing pre-populated statuses and documented justifications for exclusions, supporting Stage 1 and Stage 2 audits.

Core Features & Use Cases

  • Loads and references the Risk Treatment Plan and Annex A Review to pre-populate inclusion/exclusion status for all 93 Annex A controls.
  • Builds an internal mapping of control applicability, justifications (RT/LR/CR/BP/NA), and implementation status (IMP/PAR/NIM/NAP).
  • Outputs a structured SoA with per-control details, a Not Applicable register for exclusions, and a version-history ready for audit roadmaps.
  • Supports engagement-driven workflows from risk treatment through to the SoA, along with source-document references for traceability.

Quick Start

Run the /soa command to generate the Statement of Applicability for the current engagement.

Frequently Asked Questions about soa

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate an ISO 27001 Statement of Applicability from a risk treatment plan?

Generating an ISO 27001 Statement of Applicability requires consolidating risk treatment decisions and Annex A reviews to pre-populate inclusion statuses for all 93 controls. This process outputs a structured document with per-control details and justifications required for audits.

What is the best way to document justifications for excluded ISO 27001 Annex A controls?

Documenting justifications for excluded ISO 27001 Annex A controls requires written explanations categorized as RT, LR, CR, BP, or NA. This ensures traceability for audits by referencing source documents and building an internal mapping of control applicability.

How do I prepare a Statement of Applicability for Stage 1 and Stage 2 ISMS audits?

Preparing a Statement of Applicability for Stage 1 and Stage 2 audits involves mapping implementation statuses (IMP, PAR, NIM, NAP) against risk treatment decisions. This creates an auditable document with a Not Applicable register and version history to prevent compliance gaps.

Does the ISO 27001 SoA need to include all 93 Annex A controls?

Yes, the ISO 27001 SoA must include all 93 Annex A controls within the Clause 6.1.3(d) scope. The SoA enforces pre-populated statuses reflecting risk treatment and annex reviews, requiring documented justifications for any exclusions.

Can I automate tracking implementation status for my ISMS controls?

Automating implementation status tracking for ISMS controls involves applying statuses like Implemented, Partially Implemented, Not Implemented, or Not Applicable. This maps directly to your risk treatment plan to support audit roadmaps and engagement-driven workflows.