Risk assessment and treatment
Identify confidentiality, integrity and availability risks for each asset, evaluate them and decide on treatment: accept, mitigate, transfer or avoid.
Statement of applicability
A document justifying which Annex A controls apply and which are excluded, with their implementation status.
Security objectives and planning
Objectives consistent with the policy, measurable, with an action plan: what will be done, with what resources, who is responsible, and how results will be evaluated.
What an auditor usually asks for
- A security risk matrix with defined treatment
- An up-to-date statement of applicability (SOA)
- Security objectives with an indicator, an owner and a date
- A risk treatment plan with tracking
How to cover planning in Kimobox
- 1Log each asset's risk analysis with its treatment and its owner.
- 2Keep the statement of applicability linked to evidence for each control.
- 3Define security objectives with an indicator and let the system track them.
The statement of applicability stops being a spreadsheet: every control stays linked to its real evidence.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- ISO/IEC 27001:2022 — Information security management systems ISO/IEC · 25 October 2022
- ISO/IEC 27002:2022 — Information security controls ISO/IEC · February 2022
- Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024