{{- if .CompanyHorizontalLogoBase64}} {{imgTag .CompanyHorizontalLogoBase64 "Company Logo" "company-logo"}} {{- end}}

Statement of Applicability

{{.Title}}

Classification CONFIDENTIAL
Approver {{.Approver}}
Version {{.Version}}
Published {{.PublishedAt.Format "January 2, 2006"}}
1. Purpose
This document provides a comprehensive overview of the statement of applicability for controls within the organization. It serves as a record of which controls are applicable or not applicable to the organization, along with their relationships to regulatory requirements, contractual obligations, risk assessments, and best practices.
{{- if .FrameworkGroups}}

2. Controls

{{- range $group := .FrameworkGroups}} {{- range $group.Controls}} {{- end}} {{- end}}
Framework Control Applicability Justification for non-applicability Implemented Justification for non-implementation Justification for inclusion
Regulatory Contractual Best Practice Risk Assessment
{{$group.FrameworkName}} {{.Name}} {{- $state := boolToYesNo .Applicability}} {{- if eq $state "yes"}} Yes {{- else if eq $state "no"}} No {{- else}} - {{- end}} {{- $appStateJ := boolToYesNo .Applicability}} {{- if and (eq $appStateJ "no") .Justification}} {{.Justification}} {{- else}} - {{- end}} {{- $appState := boolToYesNo .Applicability}} {{- if eq $appState "no"}} - {{- else if .Implemented}} {{- if eq (derefString .Implemented) "IMPLEMENTED"}} Yes {{- else}} No {{- end}} {{- else}} - {{- end}} {{- $appState2 := boolToYesNo .Applicability}} {{- if eq $appState2 "no"}} - {{- else if and .Implemented (eq (derefString .Implemented) "NOT_IMPLEMENTED") .NotImplementedJustification}} {{.NotImplementedJustification}} {{- else}} - {{- end}} {{boolToYesNoDash .Regulatory}} {{boolToYesNoDash .Contractual}} {{boolToYesNoDash .BestPractice}} {{boolToYesNoDash .RiskAssessment}}
{{- end}}

3. Annexes

3.1 Column Definitions
Framework
Control
Applicability
Justification for non-applicability
Implemented
Justification for non-implementation
Justification for inclusion
For applicable controls, this section provides additional context on why the control is included, based on regulatory requirements, contractual obligations, best practices, or risk assessments.
Regulatory
  • Yes: The control is linked to one or more legal or regulatory obligations.
  • No: The control is not associated with any legal or regulatory obligations.
  • -: Not applicable (control is not applicable).
Contractual
  • Yes: The control is linked to one or more contractual obligations.
  • No: The control is not associated with any contractual obligations.
  • -: Not applicable (control is not applicable).
Best Practice
  • Yes: The control is designated as a best practice recommendation.
  • No: The control is not designated as a best practice.
  • -: Not applicable (control is not applicable).
Risk Assessment
  • Yes: The control is associated with one or more identified risks through risk mitigation measures.
  • No: The control is not currently associated with any identified risks.
  • -: Not applicable (control is not applicable).