ISMS Scoping

ISMS Scoping

The very first task when defining an ISMS is scoping. It defines the boundaries and applicability of the ISMS within an organization, ensuring that information security risks are managed effectively and consistently.

This means the scope should clearly identify which parts of the organization, processes, systems, and locations are included. There should be a single sentence scope statement in the document describing the management system framework (typically the ISMS manual), that will be presented on the certificate. A broader description in the same document would define what is in the scope and what is excluded. It must also explain any exclusions and justify why certain areas are not covered. Third parties are implicitly (or explicitly in the description) excluded, but still, you must address interfaces and dependencies between included and excluded areas and entities.

It is clear and self-explaining to have an organization chart in the documentation to present three types of colour coded boxes: in scope, supporting and out of scope functions (organizational units or roles). Supporting functions are not subject to the (internal or 3rd party) audit, but they must provide information or proofs to it.

The scope doesn’t have to align with the legal boundaries of an organization: it can be smaller, covering certain organizational units or physical locations or larger, extending to a group of companies. Larger organizations often start with a limited scope — such as a single department or service — and expand it over time. This phased approach can make implementation more manageable (reducing the scope to the necessary, will minimize controls to be implemented) while still demonstrating commitment to information security. However, even a limited scope must be justifiable and risk-based.

Another key aspect is identifying interested parties and their requirements. Stakeholders such as customers, regulators, employees, and partners often have expectations regarding information security. These expectations can directly influence the scope, especially when contractual obligations or regulatory requirements mandate specific protections. For example, a company handling personal data may need to include all systems processing that data within the ISMS scope to meet legal compliance requirements.

Please note, that the ISMS and the certification scope are typically, but not necessarily the same. You can decide to audit an identifiable subset of the ISMS. In this case the audit will assess the ISMS framework (standard body clauses) and all the relevant controls, just sampling will be based on the assets, processes and sites in the certification scope. The certification scope statement must be concise as it is presented on the 3rd party audit certificate

If an organization requires (or is obliged) to cooperate with ISO 27001 certified providers or suppliers, their certification must be carefully checked so that it covers the necessary assets and processes.

13/04/2026
DACHS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.