Expert Advice Community

Guest

Defining scope

  Quote
Guest
Guest user Created:   Mar 02, 2019 Last commented:   Mar 02, 2019

Defining scope

I am trying to scope out my ISMS. We have around 370 employees. 50 of them are remote workers. The business is an insurance brokers and the sales team rely on three brooking platforms to operate. I am unsure whether to include everything and the kind of business functions to include in the scope boundaries.
0 0

Assign topic to the user

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

Expert
Rhand Leal Mar 02, 2019

Answer:

The most important criteria you have to adopt for defining the ISMS scope are:
- which information you want to protect.
- by where this information flows, and where they are processed and stored.
- the effort to keep the environment you want to protect separated from the rest of the environment.

For example, for organizations up to 50 employees normally it is easier to define the wholly organization inside the ISMS scope. In your case, if the information is contained in specific departments, may be easier to define only these departments in the scope (if not then you should define the wholly organization inside the ISMS scope).

Regarding the remote workers, normally you do not control the environment where they are, so the se are kept out of the scope, and you treat remote access as a risk in your assessment.

These articles will provide you further explanation about defining scope:
- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/

If you believe you still need support for defining the scope, you an schedule a meeting with one of our experts at this link: https://advisera.com/27001academy/consultation/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 02, 2019

Mar 02, 2019

Suggested Topics

Guest user Created:   Dec 03, 2020 ISO 27001 & 22301
Replies: 1
0 0

Defining scope

Guest user Created:   Jun 30, 2020 ISO 27001 & 22301
Replies: 1
0 0

Defining Scope