Expert Advice Community

Guest

Defining scope

  Quote
Guest
Guest user Created:   Jul 18, 2017 Last commented:   Jul 18, 2017

Defining scope

I have completed the ISO 27001:2013 Foundations Course. In my attempt to implement what I have learnt, I encountered some issues. I am trying to define the ISMS scope for a small eshop company (about 50 employees). In my point of view, I think I should include to the ISMS the employees, the IT department, the Sales department and the accounting office and exclude the costumers and logistics partner.
0 0

Assign topic to the user

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

Expert
Rhand Leal Jul 18, 2017

Could you please give an advice about how to tackle this problem??

Answer: For such small number of employees, the most efficient way is to include all organization in the scope, because the effort to manage the interfaces and interdependencies with the areas outside the scope will be greater than consider all the areas of the organization. Customers and logistic partners are considered as interested parties that should be considered in the definition of the scope, not included in the scope itself.

This articles will provide you further explanation about defining scope:
- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/
- How to identify interested parties according to ISO 27001 and ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-identify-interested-parties-according-to-iso-27001-and-iso-22301//
- How to identify ISMS requirements of interested parties in ISO 27001 https://advisera.com/27001academy/blog/2017/02/06/how-to-identify-isms-requirements-of-interested-parties-in-iso-27001/

This material will also help you regarding defining scope:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 18, 2017

Jul 18, 2017

Suggested Topics

Guest user Created:   Dec 03, 2020 ISO 27001 & 22301
Replies: 1
0 0

Defining scope

Guest user Created:   Jun 30, 2020 ISO 27001 & 22301
Replies: 1
0 0

Defining Scope