{"id":196851,"date":"2026-07-29T22:24:20","date_gmt":"2026-07-29T20:24:20","guid":{"rendered":"https:\/\/factorialhr.com\/blog\/?p=196851"},"modified":"2026-07-29T23:18:01","modified_gmt":"2026-07-29T21:18:01","slug":"iso-27001-statement-of-applicability","status":"publish","type":"post","link":"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/","title":{"rendered":"ISO 27001 Statement of Applicability (SoA): What It Is and How to Build One"},"content":{"rendered":"<p>ISO 27001 is the international reference standard for managing information security, and within its management system, the Statement of Applicability (SoA) is one of the core documents. It&#8217;s the first thing an auditor opens when certification time comes around, and it&#8217;s where everything your organization has decided to do to protect its information comes together.<\/p>\n<p>In this article, we&#8217;ll walk through what the SoA is, what it&#8217;s for, what it needs to include, and how to build one step by step, with a sample table so you can see how it looks. If your team already runs SOC 2, this is the piece that anchors an ISO 27001 program alongside it.<\/p>\n<h2>What is the ISO 27001 Statement of Applicability (SoA)?<\/h2>\n<p>The Statement of Applicability, better known by its acronym SoA, is the document that pulls together every security control from Annex A of ISO 27001. For each one, it states whether your organization applies it or not, along with the justification and the implementation status.<\/p>\n<p>Put another way, it&#8217;s the full picture of which controls your organization has chosen to put in place, which ones it&#8217;s left out, and why. In the current version of the standard, <a href=\"https:\/\/factorialhr.com\/blog\/iso-27001\/\">ISO 27001:2022<\/a>, Annex A groups 93 controls into 4 themes, so the SoA runs through all 93 of them one by one.<\/p>\n<p>It&#8217;s worth keeping the SoA separate from your risk assessment. The risk assessment identifies the threats your organization is exposed to, while the SoA captures the decision about which controls you&#8217;ll apply to treat those risks. They&#8217;re two different documents that work together, and further down you&#8217;ll see how they connect.<\/p>\n<h2>What is it for, and why is it required?<\/h2>\n<p>The SoA plays several roles inside the <a href=\"https:\/\/factorialhr.com\/blog\/information-security-management-system\/\">ISMS<\/a>. Three of them explain why it matters so much.<\/p>\n<ul>\n<li><strong>It&#8217;s a required document for certification:<\/strong> the standard spells it out. Clause 6.1.3 d) of ISO 27001:2022 requires a Statement of Applicability that lists the necessary controls, the justification for including them, whether they&#8217;re implemented, and the reason for excluding any control. No SoA, no certification.<\/li>\n<li><strong>It connects the risk assessment to the controls:<\/strong> the SoA is the bridge between the risks you&#8217;ve identified and the measures you&#8217;ve put in place to treat them. It gives you traceability between what the standard asks for and what your organization actually does.<\/li>\n<li><strong>It&#8217;s the auditor&#8217;s main roadmap:<\/strong> when the audit starts, the auditor opens the SoA before anything else, because it hands them a complete map of the ISMS. From there, they check that the controls you say you apply are really in place and that your exclusions hold up. A weak SoA, with no justifications or unfounded exclusions, is one of the fastest routes to a nonconformity.<\/li>\n<\/ul>\n<h2>What does the SoA need to include?<\/h2>\n<p>The standard doesn&#8217;t lock you into a specific format, so you can use whatever fits your team best as long as it captures the information you need. For each Annex A control, the SoA should reflect four things.<\/p>\n<ul>\n<li><strong>The control and its description:<\/strong> the reference and name of the control exactly as it appears in Annex A, for example A.5.1 Policies for information security.<\/li>\n<li><strong>Whether it applies or not:<\/strong> the decision to include or exclude that control in your ISMS.<\/li>\n<li><strong>The justification:<\/strong> the reason behind that decision, whether the control is applied or dropped. This part is key, because justifying exclusions is exactly what the auditor digs into most.<\/li>\n<li><strong>The implementation status and evidence:<\/strong> whether the control is in place, in progress, or pending, along with a reference to the policy, procedure, or evidence that backs it up.<\/li>\n<\/ul>\n<p>A lot of organizations add extra columns, like the control owner or the risk it treats, to strengthen traceability. It&#8217;s not required, but it helps keep the document under control.<\/p>\n<h2>Sample SoA table<\/h2>\n<p>Here&#8217;s what a Statement of Applicability usually looks like in table form. This is a simplified example with just a few controls so you can see the structure.<\/p>\n<table>\n<thead>\n<tr>\n<th style=\"text-align: center;\">Control<\/th>\n<th style=\"text-align: center;\">Description<\/th>\n<th style=\"text-align: center;\">Applies?<\/th>\n<th style=\"text-align: center;\">Justification<\/th>\n<th style=\"text-align: center;\">Status<\/th>\n<th style=\"text-align: center;\">Evidence<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"text-align: center;\">A.5.1<\/td>\n<td style=\"text-align: center;\">Policies for information security<\/td>\n<td style=\"text-align: center;\">Yes<\/td>\n<td style=\"text-align: center;\">Risk identified in the risk assessment<\/td>\n<td style=\"text-align: center;\">Implemented<\/td>\n<td style=\"text-align: center;\">InfoSec Policy v1.2<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\">A.5.7<\/td>\n<td style=\"text-align: center;\">Threat intelligence<\/td>\n<td style=\"text-align: center;\">Yes<\/td>\n<td style=\"text-align: center;\">Need to stay ahead of external threats<\/td>\n<td style=\"text-align: center;\">In progress<\/td>\n<td style=\"text-align: center;\">Threat intelligence procedure<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\">A.6.7<\/td>\n<td style=\"text-align: center;\">Remote working<\/td>\n<td style=\"text-align: center;\">Yes<\/td>\n<td style=\"text-align: center;\">Part of the workforce works outside the office<\/td>\n<td style=\"text-align: center;\">Implemented<\/td>\n<td style=\"text-align: center;\">Remote work policy v2.0<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\">A.7.4<\/td>\n<td style=\"text-align: center;\">Physical security monitoring<\/td>\n<td style=\"text-align: center;\">No<\/td>\n<td style=\"text-align: center;\">The organization doesn&#8217;t have its own facilities<\/td>\n<td style=\"text-align: center;\">Not applicable<\/td>\n<td style=\"text-align: center;\">Documented justification<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\">A.8.23<\/td>\n<td style=\"text-align: center;\">Web filtering<\/td>\n<td style=\"text-align: center;\">Yes<\/td>\n<td style=\"text-align: center;\">Risk of access to malicious sites<\/td>\n<td style=\"text-align: center;\">Implemented<\/td>\n<td style=\"text-align: center;\">Corporate proxy configuration<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div class=\"factorial-banner inline-banner banner-other category-iso-27001\"\n    data-banner-id=\"192878\"\n    data-banner-type=\"other\"\n    data-category=\"ISO 27001\">\n    <div class=\"banner-content\">\n        <div class=\"banner-text\">\n                            <h4>Still building spreadsheets for your ISO 27001 audit?<\/h4>\n            \n                            <p>Factorial IT automates your inventory, access controls, and audit evidence. Your dedicated consultant handles the rest.<\/p>\n            \n                            <a href=\"https:\/\/factorialhr.com\/iso-27001\"\n                    class=\"factorial-cta-button not-prose freebie\" data-cta=\"other\" data-cta-position=\"inline-banner\">\n                    Learn more                <\/a>\n                    <\/div>\n\n        <div class=\"banner-image has-image\">\n            <img decoding=\"async\" src=\"https:\/\/factorialhr.com\/wp-content\/uploads\/2026\/06\/19135845\/EN-ISO27001.png\" class=\"not-prose\" \/>\n        <\/div>\n    <\/div>\n<\/div>\n<h2>How to build a Statement of Applicability step by step<\/h2>\n<p>Building the SoA isn&#8217;t a standalone task. It falls out naturally from the risk management work you&#8217;ve already done. Here are the usual steps to put it together.<\/p>\n<h3>1. Start with your risk assessment and risk treatment<\/h3>\n<p>The SoA isn&#8217;t your starting point. It comes out of the work you&#8217;ve done on risk. Before you touch it, you need your information assets identified, the risks they&#8217;re exposed to assessed, and the treatment options decided for each one. That&#8217;s the moment when it becomes clear which controls you need to bring each risk down.<\/p>\n<p>If you try to fill in the SoA without that groundwork, you&#8217;ll end up checking controls blindly, and the auditor will catch it right away, because there&#8217;s no traceability between the risks you identified and the controls you chose.<\/p>\n<h3>2. Select the applicable controls from Annex A<\/h3>\n<p>With your risks on the table, you go through the 93 controls in the 2022 Annex A and decide which ones apply to your organization and which don&#8217;t. The standard doesn&#8217;t require you to implement all of them, only the ones your risk level justifies, so a control can stay out if it doesn&#8217;t make sense in your context.<\/p>\n<p>Keep in mind you can also add controls that aren&#8217;t in Annex A if your risk assessment calls for it, since Annex A is a reference and not a closed list.<\/p>\n<h3>3. Document the justification, status, and evidence<\/h3>\n<p>For each control, you note whether it applies and the reason behind that decision. For the ones that apply, you add the implementation status, whether it&#8217;s in place, in progress, or pending, plus a reference to the policy, procedure, or evidence that backs it up.<\/p>\n<p>Don&#8217;t skip the justification for exclusions, because that&#8217;s exactly what the auditor reviews most. Excluding a control is perfectly valid as long as you explain why it doesn&#8217;t apply to your organization. A well-written reason is worth more than a list of checked controls with no explanation.<\/p>\n<h3>4. Review and approve the document<\/h3>\n<p>Finally, the SoA needs to be reviewed and approved by your organization&#8217;s top security authority before it&#8217;s considered valid. That formal sign-off is what turns the draft into the ISMS reference document.<\/p>\n<p>From there, it&#8217;s ready for the audit. Just remember it&#8217;s not a final version set in stone. It&#8217;s the first of many, because the SoA keeps getting updated over time.<\/p>\n<h2>How to maintain and manage the SoA<\/h2>\n<p>The SoA isn&#8217;t something you write once and file away. It&#8217;s a living document you have to review and update whenever something relevant changes in the organization, like a new risk showing up, a new asset or technology coming online, a shift in the regulatory landscape, or a change to a treatment decision. That&#8217;s why it helps to keep version control that logs every change and who approved it.<\/p>\n<p>This is where a lot of organizations get stuck. Keeping the SoA in a spreadsheet gets unmanageable the moment you have dozens of active controls, with their owners, their evidence, and their deadlines all changing at once. It&#8217;s easy for the document to fall out of date and for you to walk into the audit with expired evidence or controls that have no owner assigned.<\/p>\n<p>This is where an IT management and compliance tool like <a href=\"https:\/\/factorialhr.com\/factorial-it\">Factorial IT<\/a> makes the difference, because it covers and documents a good chunk of the technical Annex A controls that show up in your SoA.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/factorial.es\/wp-content\/uploads\/2026\/03\/23134110\/factorial-it-platform-1024x506.png\" alt=\"factorial it platform\" \/><\/p>\n<ul>\n<li><strong>Automatic IT asset inventory:<\/strong> always up to date and exportable for the audit.<\/li>\n<li><strong>Device management (MDM):<\/strong> encryption, antivirus, and patches across Mac, Windows, and Linux.<\/li>\n<li><strong>Access management:<\/strong> grants and revokes permissions based on each employee&#8217;s role.<\/li>\n<li><strong>Secure offboarding:<\/strong> shuts down every access point the moment a departure is logged in HR.<\/li>\n<li><strong>Automatic audit evidence:<\/strong> ready to export the moment the auditor asks for it.<\/li>\n<\/ul>\n<p>With your controls in place and evidence collected on an ongoing basis, keeping the SoA current stops being a last-minute scramble before the audit.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ISO 27001 is the international reference standard for managing information security, and within its management system, the Statement of Applicability (SoA) is one of the core documents. It&#8217;s the first thing an auditor opens when certification time comes around, and it&#8217;s where everything your organization has decided to do to protect its information comes together.<a href=\"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/\" class=\"read-more\"> [&#8230;]<\/a><\/p>\n","protected":false},"author":352,"featured_media":196861,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1096],"tags":[],"class_list":["post-196851","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-iso-27001-2"],"acf":{"topics":"factorial-it"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.9.1) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>ISO 27001 Statement of Applicability (SoA) | Factorial<\/title>\n<meta name=\"description\" content=\"Not sure what the ISO 27001 Statement of Applicability (SoA) is? Here&#039;s everything you need to know to build one, step by step.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ISO 27001 Statement of Applicability (SoA): What It Is and How to Build One\" \/>\n<meta property=\"og:description\" content=\"Not sure what the ISO 27001 Statement of Applicability (SoA) is? Here&#039;s everything you need to know to build one, step by step.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/\" \/>\n<meta property=\"og:site_name\" content=\"Factorial\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/people\/Factorial\/100064908455810\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-29T20:24:20+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-29T21:18:01+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/factorialhr.com\/wp-content\/uploads\/2026\/07\/29222406\/iso-27001-statement-applicability-soa.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1800\" \/>\n\t<meta property=\"og:image:height\" content=\"976\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Enrique Quiroga\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@factorialapp\" \/>\n<meta name=\"twitter:site\" content=\"@factorialapp\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Enrique Quiroga\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/\"},\"author\":{\"name\":\"Enrique Quiroga\",\"@id\":\"https:\/\/factorialhr.com\/blog\/#\/schema\/person\/576a40f0f266777ab73068c097d59014\"},\"headline\":\"ISO 27001 Statement of Applicability (SoA): What It Is and How to Build One\",\"datePublished\":\"2026-07-29T20:24:20+00:00\",\"dateModified\":\"2026-07-29T21:18:01+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/\"},\"wordCount\":1460,\"publisher\":{\"@id\":\"https:\/\/factorialhr.com\/blog\/#organization\"},\"articleSection\":[\"ISO 27001\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/\",\"url\":\"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/\",\"name\":\"ISO 27001 Statement of Applicability (SoA) | Factorial\",\"isPartOf\":{\"@id\":\"https:\/\/factorialhr.com\/blog\/#website\"},\"datePublished\":\"2026-07-29T20:24:20+00:00\",\"dateModified\":\"2026-07-29T21:18:01+00:00\",\"description\":\"Not sure what the ISO 27001 Statement of Applicability (SoA) is? Here's everything you need to know to build one, step by step.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/factorialhr.com\/blog\/#website\",\"url\":\"https:\/\/factorialhr.com\/blog\/\",\"name\":\"Factorial\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/factorialhr.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/factorialhr.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/factorialhr.com\/blog\/#organization\",\"name\":\"All-in-one business management software - Factorial\",\"url\":\"https:\/\/factorialhr.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/factorialhr.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/factorialhr.com\/wp-content\/uploads\/2023\/07\/18155144\/factorial-logo.png\",\"contentUrl\":\"https:\/\/factorialhr.com\/wp-content\/uploads\/2023\/07\/18155144\/factorial-logo.png\",\"width\":946,\"height\":880,\"caption\":\"All-in-one business management software - Factorial\"},\"image\":{\"@id\":\"https:\/\/factorialhr.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/people\/Factorial\/100064908455810\/\",\"https:\/\/twitter.com\/factorialapp\",\"https:\/\/www.linkedin.com\/company\/factorialhr\",\"https:\/\/www.youtube.com\/@factorialmedia\",\"https:\/\/www.instagram.com\/factorial\/#\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/factorialhr.com\/blog\/#\/schema\/person\/576a40f0f266777ab73068c097d59014\",\"name\":\"Enrique Quiroga\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/factorialhr.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/fcc26a14dc327372e37434cfc64f3917?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/fcc26a14dc327372e37434cfc64f3917?s=96&d=identicon&r=g\",\"caption\":\"Enrique Quiroga\"},\"url\":\"https:\/\/factorialhr.com\/blog\/author\/enrique-quiroga\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"ISO 27001 Statement of Applicability (SoA) | Factorial","description":"Not sure what the ISO 27001 Statement of Applicability (SoA) is? Here's everything you need to know to build one, step by step.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/","og_locale":"en_US","og_type":"article","og_title":"ISO 27001 Statement of Applicability (SoA): What It Is and How to Build One","og_description":"Not sure what the ISO 27001 Statement of Applicability (SoA) is? Here's everything you need to know to build one, step by step.","og_url":"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/","og_site_name":"Factorial","article_publisher":"https:\/\/www.facebook.com\/people\/Factorial\/100064908455810\/","article_published_time":"2026-07-29T20:24:20+00:00","article_modified_time":"2026-07-29T21:18:01+00:00","og_image":[{"width":1800,"height":976,"url":"https:\/\/factorialhr.com\/wp-content\/uploads\/2026\/07\/29222406\/iso-27001-statement-applicability-soa.png","type":"image\/png"}],"author":"Enrique Quiroga","twitter_card":"summary_large_image","twitter_creator":"@factorialapp","twitter_site":"@factorialapp","twitter_misc":{"Written by":"Enrique Quiroga","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/#article","isPartOf":{"@id":"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/"},"author":{"name":"Enrique Quiroga","@id":"https:\/\/factorialhr.com\/blog\/#\/schema\/person\/576a40f0f266777ab73068c097d59014"},"headline":"ISO 27001 Statement of Applicability (SoA): What It Is and How to Build One","datePublished":"2026-07-29T20:24:20+00:00","dateModified":"2026-07-29T21:18:01+00:00","mainEntityOfPage":{"@id":"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/"},"wordCount":1460,"publisher":{"@id":"https:\/\/factorialhr.com\/blog\/#organization"},"articleSection":["ISO 27001"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/","url":"https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/","name":"ISO 27001 Statement of Applicability (SoA) | Factorial","isPartOf":{"@id":"https:\/\/factorialhr.com\/blog\/#website"},"datePublished":"2026-07-29T20:24:20+00:00","dateModified":"2026-07-29T21:18:01+00:00","description":"Not sure what the ISO 27001 Statement of Applicability (SoA) is? Here's everything you need to know to build one, step by step.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/factorialhr.com\/blog\/iso-27001-statement-of-applicability\/"]}]},{"@type":"WebSite","@id":"https:\/\/factorialhr.com\/blog\/#website","url":"https:\/\/factorialhr.com\/blog\/","name":"Factorial","description":"","publisher":{"@id":"https:\/\/factorialhr.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/factorialhr.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/factorialhr.com\/blog\/#organization","name":"All-in-one business management software - Factorial","url":"https:\/\/factorialhr.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/factorialhr.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/factorialhr.com\/wp-content\/uploads\/2023\/07\/18155144\/factorial-logo.png","contentUrl":"https:\/\/factorialhr.com\/wp-content\/uploads\/2023\/07\/18155144\/factorial-logo.png","width":946,"height":880,"caption":"All-in-one business management software - Factorial"},"image":{"@id":"https:\/\/factorialhr.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/people\/Factorial\/100064908455810\/","https:\/\/twitter.com\/factorialapp","https:\/\/www.linkedin.com\/company\/factorialhr","https:\/\/www.youtube.com\/@factorialmedia","https:\/\/www.instagram.com\/factorial\/#"]},{"@type":"Person","@id":"https:\/\/factorialhr.com\/blog\/#\/schema\/person\/576a40f0f266777ab73068c097d59014","name":"Enrique Quiroga","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/factorialhr.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/fcc26a14dc327372e37434cfc64f3917?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/fcc26a14dc327372e37434cfc64f3917?s=96&d=identicon&r=g","caption":"Enrique Quiroga"},"url":"https:\/\/factorialhr.com\/blog\/author\/enrique-quiroga\/"}]}},"_links":{"self":[{"href":"https:\/\/factorialhr.com\/blog\/wp-json\/wp\/v2\/posts\/196851"}],"collection":[{"href":"https:\/\/factorialhr.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/factorialhr.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/factorialhr.com\/blog\/wp-json\/wp\/v2\/users\/352"}],"replies":[{"embeddable":true,"href":"https:\/\/factorialhr.com\/blog\/wp-json\/wp\/v2\/comments?post=196851"}],"version-history":[{"count":3,"href":"https:\/\/factorialhr.com\/blog\/wp-json\/wp\/v2\/posts\/196851\/revisions"}],"predecessor-version":[{"id":196884,"href":"https:\/\/factorialhr.com\/blog\/wp-json\/wp\/v2\/posts\/196851\/revisions\/196884"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/factorialhr.com\/blog\/wp-json\/wp\/v2\/media\/196861"}],"wp:attachment":[{"href":"https:\/\/factorialhr.com\/blog\/wp-json\/wp\/v2\/media?parent=196851"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/factorialhr.com\/blog\/wp-json\/wp\/v2\/categories?post=196851"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/factorialhr.com\/blog\/wp-json\/wp\/v2\/tags?post=196851"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}