This SOA and summary were done with the aid of AI.
02/2026
Project Title: ISO 27001 Statement of Applicability (SoA) for Azure Cyber Range
Summary
Designed and implemented a comprehensive Statement of Applicability (SoA) based on the ISO/IEC 27001:2022 standard for a cloud-hosted Cyber Range environment. This document serves as the central governance artifact, defining which information security controls are applicable, their implementation status, and the evidence used for auditing.
Key Competencies Demonstrated
- GRC Frameworks: Practical application of ISO 27001:2022 Annex A controls.
- Cloud Security Governance: Mapping abstract compliance requirements to tangible Azure technical controls (e.g., Azure Policy, Sentinel, NSGs).
- Risk Management: Justifying the exclusion of non-applicable controls (e.g., Physical Security) due to the cloud-native nature of the infrastructure.
- Audit Readiness: Establishing a clear “Evidence Reference” trail (ServiceNow CMDB, Azure Monitor logs, Tenable scans) to streamline external audits.
Technical Highlights
The SoA covers 93 controls across Organizational, People, Physical, and Technological themes. Key implementations include:
