State of Applicability
{{.Title}}
1. Purpose
This document provides a comprehensive overview of the state of applicability for controls within the organization.
It serves as a record of which controls are applicable or not applicable to the organization, along with their
relationships to regulatory requirements, contractual obligations, risk assessments, and best practices.
{{- if .FrameworkGroups}}
3. Annexes
Framework
-
The name of the compliance framework or standard to which the control belongs (e.g., ISO 27001, SOC 2, GDPR).
Control
-
The specific control identifier and name within the framework, including its section reference.
Applicability
-
Yes:
The control is applicable to the organization.
-
No:
The control is not applicable to the organization (with justification provided).
Justification for non-applicability
-
Provides the rationale when a control is not applicable. This field is empty for applicable controls.
Implemented
-
Yes:
The control has been implemented by the organization.
-
No:
The control has not been implemented (with justification provided).
-
-:
Not applicable (control is not applicable).
Justification for non-implementation
-
Provides the rationale when a control is not implemented. This field is empty for implemented controls or when the control is not applicable.
Justification for inclusion
For applicable controls, this section provides additional context on why the control is included, based on regulatory requirements, contractual obligations, best practices, or risk assessments.
Regulatory
-
Yes:
The control is linked to one or more legal or regulatory obligations.
-
No:
The control is not associated with any legal or regulatory obligations.
-
-:
Not applicable (control is not applicable).
Contractual
-
Yes:
The control is linked to one or more contractual obligations.
-
No:
The control is not associated with any contractual obligations.
-
-:
Not applicable (control is not applicable).
Best Practice
-
Yes:
The control is designated as a best practice recommendation.
-
No:
The control is not designated as a best practice.
-
-:
Not applicable (control is not applicable).
Risk Assessment
-
Yes:
The control is associated with one or more identified risks through risk mitigation measures.
-
No:
The control is not currently associated with any identified risks.
-
-:
Not applicable (control is not applicable).