Expert Advice Community

Guest

Scope review

  Quote
Guest
Guest user Created:   May 30, 2017 Last commented:   May 30, 2017

Scope review

I have one client, previously their ISMS scope is to covers the Data Centre in their own premise. Now, they have move most of their critical applications and databases to a new hosting Data Centre belong to their managed service vendor. Is the ISMS scope remain unchanged or require to further extend the scope to the new hosted Data Centre? Last time their ISMS scope is called “Operation Management Data Centre of [Company Name]”.
0 0

Assign topic to the user

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

Expert
Rhand Leal May 30, 2017

Answer: Since part of the activities that were performed by your client are now under control of its managed service vendor it has to modify the scope to reflect this new situation. The main point to consider here is how much direct control the organizations has over the applications and databases hosted on the outsourced data center. For example:

- If the organization controls both the applications and databases (the data center only provides the physical and virtual machines), only the basic infrastructure of the datacenter should be excluded from the ISMS scope.

- If the organization uses the applications as a s ervice made available by the provider, only the organization's database should be included in the ISMS scope.

This article will provide you further explanation about Scope review:
- Defining the ISMS scope if the servers are in the cloud https://advisera.com/27001academy/blog/2017/05/22/defining-the-isms-scope-if-the-servers-are-in-the-cloud/

These materials will also help you regarding Scope review:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 30, 2017

May 30, 2017