4.2.1 Establish the ISMS
The organization shall do the following. …
j) Prepare a Statement of Applicability.
A Statement of Applicability shall be prepared that includes the following:
1) the control objectives and controls selected in 4.2.1g) and the reasons for their selection;
2) the control objectives and controls currently implemented (see 4.2.1e)2)); and
3) the exclusion of any control objectives and controls in Annex A and the justification for their exclusion