Less is more: exclude non-applicable requirements – and fill the SoA automatically
Requirements that are not relevant for an organization can be classified as "not applicable" in the ISMS Cockpit. The exclusion justification stored with them is automatically transferred into the Statement of Applicability (SoA). Excluded requirements do not reduce the degree of fulfillment and are reported separately in the key figures.
Not every requirement of a standard applies to every organization. Requirements that are not relevant can be classified as "not applicable" in the ISMS Cockpit. This not only slims down the work list – the stored justification also feeds into the Statement of Applicability (SoA).
Excluding a requirement
- Open and edit the requirement: In the "Requirements" tab, click the requirement concerned. In the detail view, click "Edit" in the "General" section.
- Set the status to "Not applicable": In the "General" section, set the "Status" field to "Not applicable". The mandatory field "Exclusion justification" then appears.
- Exclusion justification and SoA: In the "Exclusion justification", state why the requirement does not apply to your organization – for example because an affected procedure or technology is not used. A note below the field points out that this justification is documented in the Statement of Applicability (SoA) – the central evidence document for audits and certification. Then click "Save and back".
What this achieves
A requirement classified as "not applicable" no longer counts towards the applicable requirements and therefore does not reduce the degree of fulfillment. In the key figures of the cockpit it is reported separately, so it remains transparent at all times what has been deliberately excluded.
Tip
Formulate the exclusion justification so that external auditors can also follow it – the SoA is an audit-relevant document.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.