Expert Advice Community

Guest

Defining scope

  Quote
Guest
Guest user Created:   Oct 17, 2018 Last commented:   Oct 17, 2018

Defining scope

I'm planning to implement ISMS however I'm stuck on the scope. Can you guide me on the creation of ISMS scope?
0 0

Assign topic to the user

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

Expert
Rhand Leal Oct 17, 2018

Answer:

According to ISO 27001, an ISMS scope must be defined in terms of information, locations or business units to be protected, considering the organization's objectives and context.
For small and mid-size organizations (up to 100 employees) often it is better to include all the organization in the scope, because the effort to keep only a part of the organization in the scope is not worthy. For bigger organizations defining a smaller scope may be better to reduce the costs and effort to what really matters for business objectives.

These articles will provide you further explanation about defining scope:
- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/

These materials will also help you regarding defining scope:
- Book Secu re & Simple: A Small-Business Guide to implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Oct 17, 2018

Oct 17, 2018

Suggested Topics

Guest user Created:   Dec 03, 2020 ISO 27001 & 22301
Replies: 1
0 0

Defining scope

Guest user Created:   Jun 30, 2020 ISO 27001 & 22301
Replies: 1
0 0

Defining Scope