statement-of-applicability-author

Generate ISO 27001 and ISO 42001 Statements of Applicability from Annex A tables and risk-treatment outputs.

2|Updated Jul 6, 2026
One-click install
npx skills add https://github.com/nguyenpv1980-wq/Project-Aegis --skill statement-of-applicability-author
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: statement-of-applicability-author
Source: https://github.com/nguyenpv1980-wq/Project-Aegis/tree/main/.claude/skills/statement-of-applicability-author
Command: npx skills add https://github.com/nguyenpv1980-wq/Project-Aegis --skill statement-of-applicability-author

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes assets (resource) components.

What problem does it solve?

This Skill helps compliance teams write or update an ISO Statement of Applicability so every Annex A control is explicitly marked applicable or excluded with a defensible justification tied to risk treatment or obligation.

Core Features & Use Cases

  • ISO 27001 and ISO 42001 support: Produces SoAs for either standard or a combined document with per-standard applicability kept distinct.
  • Audit-ready control tracing: Forces each inclusion to cite risk-treatment decisions or obligations and each exclusion to have a concrete, verifiable rationale.
  • Controlled-document discipline: Captures versioning, named approver, review cadence, implementation status, and evidence hooks for downstream audit work.
  • Use case: A security team finishing certification prep can use this Skill to turn their risk register and licensed Annex A table into a reviewable SoA draft instead of a vague checklist.

Quick Start

Use the statement-of-applicability-author skill to draft a controlled SoA from the licensed Annex A table and our risk-treatment decisions, with per-control applicability, justification, status, and approver metadata.

Frequently Asked Questions about statement-of-applicability-author

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a Statement of Applicability for ISO 27001 using risk treatment decisions?

To write a Statement of Applicability, map your licensed Annex A entries and risk treatment outputs to per-control applicability decisions, ensuring each inclusion cites risk traceability and each exclusion has a verifiable rationale.

Can I create a combined Statement of Applicability for ISO 27001 and ISO 42001?

Yes, you can create a combined dual-standard Statement of Applicability document while keeping per-standard applicability decisions distinct for both ISO 27001 and ISO 42001 compliance requirements.

What do I need to prepare before drafting an audit-ready SoA?

Before drafting an audit-ready SoA, you need exact Annex A entries, risk traceability data, implementation-status mapping to a control catalog, and controlled-document metadata like versioning and named approvers.

How do you justify excluded controls in an ISO Statement of Applicability?

Excluded controls in an ISO Statement of Applicability require a concrete, verifiable rationale tied to risk treatment decisions or obligations, ensuring the exclusion is fully defensible during certification audits.

What is the best way to maintain controlled-document discipline for an SoA during certification prep?

Maintain controlled-document discipline for an SoA by capturing versioning, named approver, review cadence, implementation status, and evidence hooks to support downstream audit work and certification prep.