Statement of Applicability (SOA): the Statement of Applicability report is an overview of the status of the Risk Treatment. A Statement of Applicability is a list of all Controls from the Standard used to perform the Risk Treatment which have been labelled as Implemented, Not Implemented, Future Controls or Not Applicable. The descriptions entered for each respective control are also printed out. The status of the Risk Treatment is also displayed graphically. The report is useful for the managers of business units, customers, and agencies, e.g. the Data Protection Authority, which require a declaration of the security of the Risk Treatment in question. It can also be submitted to auditors. Risk Treatment – Future controls (simple report): this report provides an overview of all Future Controls that have been defined for a given Risk Treatment. They are ranked according to date, so that the Control with the earliest date of implementation is shown first. The Executive Summary report:·A great overview of Security Risk and Ratio of Controls. All calculations are shown graphically in a color coded way and gives the management key information on a single sheet. Risk Treatment: All risks are listed along with their base, current and future security risk. The list is grouped by the Risk Treatment. Users can sort Risks by Base Security Risk, Current Security Risk, or Future Security Risk. This report provides a total overview of the risks and the treatment for each of them. Controls With Assets: This report will show you all the Controls in your Risk Treatment, the name of the Control, Status of the Control, and Assets associated with the Control. Risk With Controls: This report is only available to those using the Local Reports. This report is useful when information is needed on whether or not a control has been implemented for specific risks (image 16.1). 9.2.Risk Treatment Reports