SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Defining scope

  Quote
Guest
Guest user Created:   Jul 13, 2019 Last commented:   Jul 13, 2019

Defining scope

I would like a small piece of advice if possible. I have been asked to look at an ISO 27001 implementation in my company. We are a global chemical company and have our IT department mainly located in XXXX. We have some additional IT support globally but the majority is in XXXX. I have been asked by CIO if it is possible to scope just the IT Department for ISO 27001, and have been also asked if it would be possible to just scope the IT Department in XXXX (excluding the other global IT support).
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jul 13, 2019

I was wondering if you think it is possible to scope one department in one location? If possible, what do you see as the main challenges here?

Any advice or guidance is greatly appreciated, or even a reference to articles that may help me.

Answer:

The ISO 27001 scope can be limited to part of the organization (e.g., business unit, process, or location), but you have to note that an organization should evaluate first if this separation will not bring more additional effort than considering all the organization as part of the scope.

Many larger companies limit the scope of ISO 27001 implementation on IT department and/or one location, and in most cases this works well.

These articles will provide you further explanation about scope definition:
- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/
- Defining the ISMS scope if the servers are in the cloud https://advisera.com/27001academy/blog/2017/05/22/defining-the-isms-scope-if-the-servers-are-in-the-cloud/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 13, 2019

Jul 13, 2019

Suggested Topics

Guest user Created:   Dec 03, 2020 ISO 27001 & 22301
Replies: 1
0 0

Defining scope

Guest user Created:   Jun 30, 2020 ISO 27001 & 22301
Replies: 1
0 0

Defining Scope