Expert Advice Community

Guest

ISMS scope definition

  Quote
Guest
Guest user Created:   Feb 20, 2017 Last commented:   Feb 20, 2017

ISMS scope definition

Can we restrict our scope of ISMS to IT Department and get certified for it for ISO 27001?
0 0

Assign topic to the user

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

Expert
Rhand Leal Feb 20, 2017

Answer: Theoretically you can, but in terms of added value this may not be the most effective way because the most sensitive business information will be probably left outside of this scope, since information also exists and flows outside information systems, and the IT department cannot be responsible for the information it doesn't own or control.

Besides that, when considering small and mid-sized business, the costs and effort involved to limit the scope very often will be higher then implementing the ISMS in the whole company.
This article will provide you further explanation about ISMS scope definition:

- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/

These materials will also help you regarding ISMS scope definition:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 20, 2017

Feb 20, 2017

Suggested Topics