Defining scope
Assign topic to the user
I researched in Editals and RFPs but did not say which processes should be certified in ISO 270001. Could you help me?
Answer: An ISMS scope can be defined in terms of processes, locations and/or information to be protected. Considering that, these are examples of how you can defined your scope:
- Processes related to the provision of hosting, colocation and cloud services to organization's customers (the detail of the processes can be developed later during the risk assessment process)
- Processes performed at physical locations XXX, YYY, ZZZ, etc.
- Information related to the provision of hosting, colocation and cloud services to organization's customers (the detail about the type of information can be identified la ter during the risk assessment process).
These articles will provide you further explanation about defining scope:
- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/
These materials will also help you regarding defining scope:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course//
Comment as guest or Sign in
May 22, 2018