Answer : The SoA need to include a list in the security controls from Annex A of ISO/IEC 27001. It must also demonstrate the steps to implement Each and every control, which include any modifications or exclusions and references concerning policies, procedures, or documents.Existing – Context to your Organization – It demands an organization