Under ISO/IEC 27001, what is the purpose of a Statement of Applicability (SoA)?
-
A
To document all identified information security risks
-
B
To list all controls selected or excluded and provide justification for each
-
C
To define the scope of the ISMS
-
D
To record the results of internal audits