Of all the documentation required for ISO 27001 certification, one tends to draw the closest attention from auditors: the Statement of Applicability. It's often the first document they turn to, and there's good reason for that. It's where your risk assessment, your control choices, and your entire ISMS come together into a single, coherent story, one that shows not just what you've done, but why.