ISO 27001 CONTROL GOVERNANCE. HUMAN ACCOUNTABILITY.
Statement of Applicability Software for US Teams
ISO 27001 Control Decisions, Connected Evidence and Human Accountability
Zebsoft helps US security and compliance teams maintain a controlled Statement of Applicability for their ISO/IEC 27001 information security management system. Connect control decisions, justifications, implementation status, owners and evidence across US facilities, remote teams and service providers. Keep customer security commitments and risk treatment connected to the people responsible for delivery.
ZAP AI may examine approved information, analyze relationships and identify matters for review. AI output can be incomplete or incorrect and must be checked against its sources. Authorized people determine control needs, verify evidence, approve the SoA and accept risk.

WHAT THE SoA ACTUALLY GOVERNS
A Controlled Record of Security Decisions
The Statement of Applicability is not a catalog of software features and it is not a declaration that every Annex A control must be adopted. It records which controls the organization has determined are necessary, why controls are included, whether they are implemented and why any Annex A controls are excluded.
Zebsoft structures and connects the record. The organization decides what is necessary and remains accountable for that decision.
THE GOVERNED SoA LIFECYCLE
From Scope and Risk to Review and Approval
Zebsoft can organize the work around the SoA while keeping decision authority with competent people.
ONE CONNECTED CONTROL REGISTER
What Zebsoft Statement of Applicability Software Controls
The platform provides structure, routing and traceability around each control record. Configuration should reflect the organization’s own ISMS design and authority model.
RESPONSIBLE AI WITHIN THE ISMS
Interrogate, Analyze and Challenge—Never Invent Responsibility
ZAP AI is used as an analytical assistant over information the organization has authorized it to examine. It can help a reviewer navigate a large SoA, compare related records and bring possible inconsistencies to attention. Its output is a prompt for human investigation, not an organizational decision.
We deliberately reject the idea that an AI should generate a polished but unsupported SoA. A plausible paragraph is not evidence. A suggested justification is not risk acceptance. A statistical answer is not management approval.
AI does not approve the SoA. Scope, applicability, exclusion justifications, residual-risk acceptance and implementation claims require authorized human decisions. Reviewers must check AI output against genuine records before using it.

DECISIONS BELONG TO PEOPLE
Human Accountability Is Designed Into the Workflow
Responsibility cannot be delegated to an algorithm. Zebsoft can route decisions to the right role and retain the record of review, but the organization defines who is competent and authorized.
An AI-generated recommendation may inform these people. It never replaces their competence, authority, professional judgment or recorded decision.
ISO/IEC 27001:2022 ANNEX A
Organize the Reference Controls Without Losing Risk Context
The 2022 control set is organized into four themes. Zebsoft can present those controls alongside organization-specific and externally required controls, while the organization determines what is necessary.
ISO/IEC 27002 provides implementation guidance for information-security controls. It does not replace the organization’s own risk treatment, design choices or accountability.

FROM ASSERTION TO EXAMINABLE EVIDENCE
An Attachment Is Not Automatically Proof of Control Effectiveness
A policy can show that a control was designed. A configuration record may show that it exists. Logs, samples, tests, interviews, incident outcomes and audit results may provide evidence about whether it operates and achieves the intended result. Those are different assurance questions.
Zebsoft can connect each control to several evidence types and retain review history. The reviewer decides whether the evidence is authentic, relevant, sufficient, current and within scope.
KEEP THE SoA CURRENT
Review When the Organization or Its Risk Changes
A review date helps, but material change should also prompt attention. ZAP can monitor connected records and raise a review task without silently rewriting the approved SoA.
New or changed AI use is also a review trigger
When the organization adopts AI services, it should assess information assets, data flows, suppliers, access, privacy, accuracy, security, retention and human-oversight risks. The ISMS can govern those risks; ISO/IEC 42001 may provide a complementary management-system framework for responsible AI use. The two standards should not be presented as interchangeable.
A REAL-WORLD REVIEW ROUTE
When a US Customer Review Exposes a Control Gap
A US service provider is preparing a customer security response. Its access-control record is marked implemented, but an acquisition has introduced another identity system. An AI observation starts a review; a competent owner verifies the facts.
The result is a traceable chain from machine-raised observation to human examination, evidence and authorized decision.
MANAGEMENT AND AUDIT VIEW
Report the Position Without Hiding Its Limitations
Dashboards and exports can help management and auditors navigate the SoA, but presentation should not turn uncertainty into a green badge. A useful view distinguishes complete records from overdue reviews, unsupported claims, open actions and unresolved exceptions.
The organization defines reporting criteria and decides what the indicators mean. Zebsoft displays recorded information; it does not certify that the organization conforms.

CONNECTED ISMS GOVERNANCE
The SoA Makes More Sense When Its Sources Remain Connected
A static export may satisfy a document request, but the working governance value comes from links to the records that explain and test the control position.
CLEAR PRODUCT BOUNDARIES
What Zebsoft Supports—and What the Organization Must Supply
INFORMED IMPLEMENTATION
Standards References and Practical Questions
Use the licensed standards and competent advice applicable to your organization. Product content is informative and is not certification, legal advice or a substitute for the standard.
Can AI write our Statement of Applicability?
It can assist analysis and drafting for human review, but Zebsoft’s approach is not to manufacture an approved SoA. Scope, risk treatment, applicability, exclusions, evidence, risk acceptance and approval require authorized human judgment.
Does every Annex A control have to be implemented?
No blanket answer should be generated. The organization determines necessary controls through risk treatment and other requirements, uses Annex A as a reference and justifies exclusions in its SoA.
Does linked evidence prove effectiveness?
No. It makes evidence accessible and traceable. Competent reviewers and auditors still evaluate authenticity, relevance, sufficiency, currency, operation and effectiveness.
Can Zebsoft guarantee certification?
No. Zebsoft provides governance capability. Certification depends on the organization’s ISMS, implementation, evidence and independent assessment against applicable requirements.
SEE THE GOVERNED SoA WORKFLOW
Bring a Real Control Decision—Not a Generic Checklist
Bring a real US customer requirement, an access-control review or a control shared across several facilities. We can demonstrate how ZAP connects risk, ownership, evidence and approval. ZEBSOFT is UK-based; discuss US time-zone coverage, AWS London hosting and rollout requirements during scoping.

