The Statement of Applicability module enables security controls to be systematically recorded and evaluated in accordance with ISO/IEC 27001 requirements. For each control, its applicability, implementation status and method of implementation can be defined, together with appropriate justification where a control is deemed not applicable.
WebArat links individual controls to security documentation maintained in the Documentation module, making it possible to demonstrate directly how and where a specific control is implemented and managed within the organisation.
The Statement of Applicability provides a clear and up-to-date overview of the status of security controls and serves as an important basis for ISMS management, internal controls and audits.