Control applicability is the decision about whether a control belongs in the organization’s security program and why.
The decision should consider:
- Scope and critical business services
- Data, systems, identities, and suppliers
- Threats and vulnerabilities
- Legal, regulatory, contractual, or customer expectations
- Existing safeguards and planned treatment
Applicable does not mean implemented. A control can be relevant but still in progress, partially implemented, or missing evidence. Keeping applicability, implementation status, and evidence status separate makes reporting more honest and useful.
