DRAFT — REQUIRES REVIEW BY EXTERNAL ISO 27001 CONSULTANT AND SIGN-OFF BY BRITIAI CTO BEFORE USE IN BID OR AUDIT.
ISO/IEC 27001:2022 — Statement of Applicability (SoA)
Document ID: ISO02 Version: 0.1 (Draft) Date: 15 June 2026 Owner: BritiAI CISO (interim: CTO) Standard reference: ISO/IEC 27001:2022 Clause 6.1.3 d) and Annex A (93 controls across A.5, A.6, A.7, A.8)
Legend
- Applicability: A = Applicable, X = Excluded
- Status: I = Implemented, P = Partial, PL = Planned, NA = Not Applicable
- Owners: CTO, CISO (interim CTO), Head of Engineering (HoE), Head of People (HoP), DPO, Head of Ops (HoO)
- Evidence references point to documents in the BritiAI ISMS document library (placeholders pending external review).
A.5 — Organisational controls (37)
| ID | Control | Applic. | Justification | Status | Evidence | Owner |
|---|---|---|---|---|---|---|
| A.5.1 | Policies for information security | A | Top-level policy required by Clause 5.2 | P | ISMS-POL-001 | CTO |
| A.5.2 | Information security roles and responsibilities | A | Roles required for ISMS operation | P | Org chart, RACI | CTO |
| A.5.3 | Segregation of duties | A | Reduces risk of unauthorised change in cloud/MLOps | P | IAM matrix | HoE |
| A.5.4 | Management responsibilities | A | Required by Clause 5.1 | P | Board minutes | CTO |
| A.5.5 | Contact with authorities | A | ICO, NCSC, NHS contacts | PL | Contacts register | DPO |
| A.5.6 | Contact with special interest groups | A | CiSP, NCSC, AI safety bodies | PL | Membership log | CISO |
| A.5.7 | Threat intelligence | A | NEW in 2022; required for cloud/AI threat landscape | PL | TI feed config | CISO |
| A.5.8 | Information security in project management | A | All eng projects covered | P | Project template | HoE |
| A.5.9 | Inventory of information and other associated assets | A | Asset register required | P | Asset register v0.3 | HoO |
| A.5.10 | Acceptable use of information and other associated assets | A | AUP for all staff | I | AUP-POL-002 | HoP |
| A.5.11 | Return of assets | A | Leaver process | P | Leaver checklist | HoP |
| A.5.12 | Classification of information | A | NHS data sensitivity drives this | P | Classification scheme | DPO |
| A.5.13 | Labelling of information | A | Tied to classification | PL | Label schema | DPO |
| A.5.14 | Information transfer | A | Customer data ingress/egress | P | Transfer policy | CISO |
| A.5.15 | Access control | A | IAM foundation | P | IAM policy | HoE |
| A.5.16 | Identity management | A | SSO via IdP | I | IdP config | HoE |
| A.5.17 | Authentication information | A | Secrets, passwords, keys | P | Secrets policy | HoE |
| A.5.18 | Access rights | A | JML process | P | JML runbook | HoP/HoE |
| A.5.19 | Information security in supplier relationships | A | Critical for Votee/Beever flow-down | P | Supplier policy | HoO |
| A.5.20 | Addressing information security within supplier agreements | A | Inter-co MSA + DPAs | P | MSA template | Legal |
| A.5.21 | Managing information security in the ICT supply chain | A | Cloud + SaaS chain | PL | Supply chain register | CISO |
| A.5.22 | Monitoring, review and change management of supplier services | A | Annual supplier review | PL | Review log | HoO |
| A.5.23 | Information security for use of cloud services | A | NEW in 2022; UK region enforcement | P | Cloud security std | HoE |
| A.5.24 | Information security incident management planning and preparation | A | IR plan required | P | IR plan v0.2 | CISO |
| A.5.25 | Assessment and decision on information security events | A | Triage criteria | PL | Triage SOP | CISO |
| A.5.26 | Response to information security incidents | A | Required | P | IR runbooks | CISO |
| A.5.27 | Learning from information security incidents | A | Post-incident review | PL | PIR template | CISO |
| A.5.28 | Collection of evidence | A | Forensics readiness | PL | Evidence SOP | CISO |
| A.5.29 | Information security during disruption | A | BCP overlap | PL | BCP doc | HoO |
| A.5.30 | ICT readiness for business continuity | A | NEW in 2022 | PL | ICT BCP | HoE |
| A.5.31 | Legal, statutory, regulatory and contractual requirements | A | UK GDPR, DPA, NHS contracts | P | Legal register | Legal/DPO |
| A.5.32 | Intellectual property rights | A | Model weights, code, OSS licences | P | IP register | Legal |
| A.5.33 | Protection of records | A | Records retention | P | Retention schedule | DPO |
| A.5.34 | Privacy and protection of PII | A | UK GDPR | P | DPIA process | DPO |
| A.5.35 | Independent review of information security | A | Internal audit + external Stage 2 | PL | Audit plan | CTO |
| A.5.36 | Compliance with policies, rules and standards for information security | A | Conformance checks | PL | Conformance log | CISO |
| A.5.37 | Documented operating procedures | A | Runbooks | P | Runbook library | HoE |
A.6 — People controls (8)
| ID | Control | Applic. | Justification | Status | Evidence | Owner |
|---|---|---|---|---|---|---|
| A.6.1 | Screening | A | Pre-employment checks (NHS context requires BPSS-equivalent for cleared staff) | P | Screening SOP | HoP |
| A.6.2 | Terms and conditions of employment | A | Security clauses in contracts | I | Employment contract template | HoP |
| A.6.3 | Information security awareness, education and training | A | Annual + role-specific | P | LMS records | HoP |
| A.6.4 | Disciplinary process | A | For policy breach | I | Disciplinary policy | HoP |
| A.6.5 | Responsibilities after termination or change of employment | A | Leaver obligations | P | Leaver checklist | HoP |
| A.6.6 | Confidentiality or non-disclosure agreements | A | All staff + suppliers | I | NDA templates | Legal |
| A.6.7 | Remote working | A | UK remote workforce | P | Remote work policy | HoP |
| A.6.8 | Information security event reporting | A | Reporting channel | P | Reporting SOP | CISO |
A.7 — Physical controls (14)
| ID | Control | Applic. | Justification | Status | Evidence | Owner |
|---|---|---|---|---|---|---|
| A.7.1 | Physical security perimeters | A | Office perimeter; cloud DC handled by provider attestation | P | Office assessment | HoO |
| A.7.2 | Physical entry | A | Office access | P | Access log | HoO |
| A.7.3 | Securing offices, rooms and facilities | A | Office hygiene | P | Office SOP | HoO |
| A.7.4 | Physical security monitoring | A | NEW in 2022 | PL | CCTV/log review | HoO |
| A.7.5 | Protecting against physical and environmental threats | A | Office fire/flood | P | H&S risk | HoO |
| A.7.6 | Working in secure areas | A | Sensitive work zones | PL | Zone SOP | HoO |
| A.7.7 | Clear desk and clear screen | A | All staff | P | CDS policy | HoP |
| A.7.8 | Equipment siting and protection | A | Office equipment | P | Asset register | HoO |
| A.7.9 | Security of assets off-premises | A | Remote-work laptops | P | MDM policy | HoE |
| A.7.10 | Storage media | A | Encrypted only; no removable media policy | P | Media policy | CISO |
| A.7.11 | Supporting utilities | A | Inherited from cloud provider; office UPS where applicable | P | Provider attestation | HoO |
| A.7.12 | Cabling security | A | Office cabling | P | Office build doc | HoO |
| A.7.13 | Equipment maintenance | A | Endpoint maintenance | P | MDM patch records | HoE |
| A.7.14 | Secure disposal or re-use of equipment | A | Certified wipe/destroy | PL | Disposal certs | HoO |
A.8 — Technological controls (34)
| ID | Control | Applic. | Justification | Status | Evidence | Owner |
|---|---|---|---|---|---|---|
| A.8.1 | User end point devices | A | Managed endpoints only | P | MDM baseline | HoE |
| A.8.2 | Privileged access rights | A | Admin role minimisation | P | PAM design | HoE |
| A.8.3 | Information access restriction | A | RBAC/ABAC | P | IAM matrix | HoE |
| A.8.4 | Access to source code | A | Repo access controls | I | Repo perms | HoE |
| A.8.5 | Secure authentication | A | MFA enforced | I | IdP MFA policy | HoE |
| A.8.6 | Capacity management | A | Cloud autoscale + monitoring | P | Capacity dashboard | HoE |
| A.8.7 | Protection against malware | A | EDR + email filtering | P | EDR console | CISO |
| A.8.8 | Management of technical vulnerabilities | A | Scanning + patch SLA | P | Vuln dashboard | CISO |
| A.8.9 | Configuration management | A | IaC + drift detection | P | IaC repo | HoE |
| A.8.10 | Information deletion | A | NEW in 2022; data deletion SLAs | PL | Deletion SOP | DPO |
| A.8.11 | Data masking | A | NEW in 2022; needed for training data pipelines | PL | Masking std | HoE |
| A.8.12 | Data leakage prevention | A | NEW in 2022; DLP in M365/Google + egress controls | PL | DLP config | CISO |
| A.8.13 | Information backup | A | Cloud-native backup | P | Backup policy | HoE |
| A.8.14 | Redundancy of information processing facilities | A | Multi-AZ within UK region | P | Architecture doc | HoE |
| A.8.15 | Logging | A | Centralised SIEM | P | SIEM config | CISO |
| A.8.16 | Monitoring activities | A | NEW in 2022; 24/7 alerting | PL | Monitoring SOP | CISO |
| A.8.17 | Clock synchronisation | A | NTP from authoritative source | I | NTP config | HoE |
| A.8.18 | Use of privileged utility programs | A | Restricted | P | PAM policy | HoE |
| A.8.19 | Installation of software on operational systems | A | Allowlisting | P | MDM allowlist | HoE |
| A.8.20 | Networks security | A | VPC segmentation, WAF | P | Network design | HoE |
| A.8.21 | Security of network services | A | TLS everywhere | I | TLS policy | HoE |
| A.8.22 | Segregation of networks | A | Prod/non-prod/NHS tenant isolation | P | Network design | HoE |
| A.8.23 | Web filtering | A | NEW in 2022; via EDR/secure web gateway | PL | SWG config | CISO |
| A.8.24 | Use of cryptography | A | TLS 1.2+, AES-256 at rest, FIPS-aligned KMS | P | Crypto std | HoE |
| A.8.25 | Secure development lifecycle | A | SDLC required | P | SDLC policy | HoE |
| A.8.26 | Application security requirements | A | Security reqs per project | P | Security reqs template | HoE |
| A.8.27 | Secure system architecture and engineering principles | A | Threat modelling | PL | Threat model template | HoE |
| A.8.28 | Secure coding | A | NEW in 2022; secure coding std | P | Coding std | HoE |
| A.8.29 | Security testing in development and acceptance | A | SAST/DAST + manual | P | CI security gates | HoE |
| A.8.30 | Outsourced development | A | Votee/Beever code contributions governed | P | Supplier dev SOP | HoE |
| A.8.31 | Separation of development, test and production environments | A | Environment isolation | P | Env design | HoE |
| A.8.32 | Change management | A | Change ticketing | P | Change policy | HoE |
| A.8.33 | Test information | A | Synthetic/anonymised test data; no NHS data in non-prod | PL | Test data SOP | DPO |
| A.8.34 | Protection of information systems during audit testing | A | Read-only audit creds | PL | Audit access SOP | CISO |
Summary counts (target Stage 1):
- Total Annex A controls: 93
- Applicable: 93 (no full exclusions; some controls inherited from cloud provider with reduced direct implementation burden)
- Implemented (I): ~10
- Partial (P): ~55
- Planned (PL): ~28
This profile is consistent with an SME at Stage 1 readiness. The Gap Analysis (ISO03) prioritises the Planned items for closure ahead of Stage 2.
End of document.
