Skip to main content
botBrains is not yet ISO 27001 certified. We are preparing our ISMS and writing these policies as part of pursuing certification, and we fully intend to get our controls attested.

Download as PDF

The Statement of Applicability (SoA) records how botBrains applies each of the 93 ISO/IEC 27001:2022 Annex A controls: whether the control is in scope, which policy governs it, and its implementation status. It’s the index that ties the policies to the controls they satisfy.

How to read this

  • Applicable. Whether the control is in scope. The only exclusion is outsourced development, which botBrains doesn’t do.
  • Implemented. Yes (operating), Inherited (operated by a certified provider), Partial; … (in place, with the action that finishes it), or No; … (applicable, with the action that starts it).
  • Policy. The governing policy, with the specifics that add detail.

A.5 Organizational controls

A.6 People controls

A.7 Physical controls

A.8 Technological controls

ISO 27001

How the ISMS fits together, with the full policy list.