ISO 27001, from the risk assessment to the Statement of Applicability
ISO 27001 is certifiable, which means an auditor will ask you to produce the risk assessment, the treatment decisions and the evidence that each selected control operates. Dimeri holds all three against the clause and the Annex A reference they answer to.
What ISO 27001 requires
ISO 27001 specifies the requirements for an information security management system. Unlike ISO 31000, it is a certifiable management system standard, so the wording matters: clauses 4 to 10 use shall, and an accredited auditor tests each one. The 2022 revision restructured Annex A from 114 controls in 14 clauses into 93 controls across four themes, organisational, people, physical and technological.
The centre of the standard is the risk process in clause 6. You define a risk assessment method, apply it consistently, identify risks to the confidentiality, integrity and availability of information, and decide a treatment for each. Clause 6.1.3 then requires you to compare the controls you selected against Annex A and produce a Statement of Applicability listing every Annex A control, whether it is applicable, the justification, and whether it is implemented. That document is the first thing most auditors ask for.
The rest is the management system around it: context and interested parties, leadership and policy, competence and awareness, documented information, operational planning, monitoring and measurement, internal audit, management review, nonconformity and corrective action. Certification is not granted on the strength of the controls alone. It is granted on evidence that the system runs.
The clauses Dimeri tracks
Dimeri holds the management system clauses and the Annex A control set in one structure, so the Statement of Applicability is generated rather than maintained by hand.
Context, scope and leadership
The organisation and its interested parties understood, the ISMS scope defined and defensible, and top management demonstrably accountable for it.
- Scope statement held with its boundaries and exclusions
- Interested parties and their requirements recorded
- Information security policy with approval and review dates
- Roles and responsibilities assigned to named individuals
Risk assessment and treatment
A defined and repeatable risk assessment method, applied consistently, with a treatment decision recorded for every risk.
- Assessment criteria and acceptance thresholds configured once
- Risks to confidentiality, integrity and availability scored
- Treatment option and owner recorded per risk
- Residual risk accepted by an accountable person
Statement of Applicability
Every Annex A control listed with its applicability, the justification for inclusion or exclusion, and its implementation status.
- All 93 Annex A controls held as a single register
- Justification recorded against each decision
- Implementation status derived from control evidence
- SoA exported for the auditor from live data
The control set
Organisational, people, physical and technological controls, each with an owner and evidence that it operates rather than that it exists.
- Controls mapped to the risks they treat
- Test schedule and results per control
- Evidence attached at the point the control runs
- Shared controls credited to POPIA and other frameworks
Support and operation
Competence, awareness, communication and documented information, plus the operational planning and control that keeps the system running.
- Awareness training tracked to the individual
- Document control with versions and review dates
- Change and supplier processes held as controls
- Operational records retained against their requirement
Evaluation and improvement
Monitoring and measurement, internal audit, management review, and nonconformity and corrective action.
- Internal audit programme covering the whole ISMS
- Management review inputs assembled through the year
- Nonconformities tracked to closure with root cause
- Effectiveness measures reported rather than asserted
How Dimeri covers ISO 27001
Certification turns on evidence, and evidence is what spreadsheets lose. Dimeri is built so the auditor's requests are searches rather than projects.
The Statement of Applicability writes itself
Because every Annex A control carries its applicability decision, justification and implementation evidence in one place, the SoA is a report. Maintaining it as a separate spreadsheet is how it drifts out of step with reality between audits.
Risk to control to evidence, in one chain
Clause 6.1.3 expects the controls you selected to trace back to the risks that justified them. Dimeri holds that link directly, so the auditor's question about why a control exists has an answer on screen.
Shared credit with POPIA
A control satisfying Annex A and POPIA section 19 is written once and counted in both. For South African organisations doing ISO 27001 and POPIA together, that overlap is most of the work.
Surveillance audits without the scramble
Annual surveillance is where most certified organisations struggle, because the system quietly stopped running after certification. Scheduled control tests, internal audits and management reviews keep it visibly alive.
Getting ISO 27001 in place
- 1
Define the scope honestly
Scope is the decision that shapes everything after it. Too narrow and the certificate is worth little commercially; too broad and the first certification becomes unmanageable. It is recorded with its boundaries and its exclusions so the auditor sees the reasoning.
- 2
Run the risk assessment
Assets, threats and vulnerabilities are assessed against criteria you set once and apply consistently. Consistency is what an auditor tests, more than the specific numbers.
- 3
Select controls and build the SoA
Treatment decisions drive control selection, which is then compared against all 93 Annex A controls. Every inclusion and exclusion carries a justification, and the Statement of Applicability is produced from that record.
- 4
Run the system and evidence it
Control tests, awareness training, internal audit and management review run on schedule with owners. By the certification audit the evidence already exists with its dates rather than being assembled in the preceding fortnight.
ISO 27001 questions
How many controls are in ISO 27001:2022?
Annex A of the 2022 edition contains 93 controls grouped into four themes: organisational, people, physical and technological. The 2013 edition had 114 controls across 14 clauses. Organisations transitioning from the older edition need to map their existing controls onto the new structure, which Dimeri holds as a single register either way.
What is the Statement of Applicability?
It is the document required by clause 6.1.3(d) listing every Annex A control, whether it applies to your ISMS, the justification for including or excluding it, and whether it is implemented. It is usually the first document an auditor asks for, and the one most likely to have drifted out of date when it lives in a separate spreadsheet.
Can Dimeri get us certified?
No platform can. Certification is granted by an accredited certification body after a two stage audit. What Dimeri does is hold the management system so the evidence the auditor asks for already exists, which is where most first attempts lose time.
How does ISO 27001 relate to POPIA?
POPIA section 19 requires appropriate, reasonable technical and organisational measures and refers to generally accepted information security practices. ISO 27001 is the most commonly cited expression of those practices in South Africa. Dimeri maps a control once and credits it to both, which is why organisations running the two together do far less duplicate work.
Is this a substitute for the standard itself?
No. ISO 27001 is a copyrighted document published by ISO and should be obtained from ISO or a national standards body if you intend to certify against it. This page describes how Dimeri holds the management system.
Go further on ISO 27001
Put ISO 27001 on one register
Every requirement mapped to a control with a named owner, the evidence held against it, and one view of where you stand.