SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Defining the Scope

  Quote
Guest
Guest user Created:   Aug 14, 2020 Last commented:   Aug 14, 2020

Defining the Scope

I would like to start off with a scope that includes the information stored in our datacenters.
 
But, when I look at the ISO 27001 standard, it states quite clearly that;

When determining the scope, the organization shall consider;
a)      the external and internal issues referred to 4.1 (Understanding the organization and its context)
b)      the requirements referred to in 4.2 (Understanding the needs and expectations of interested parties)
c)       interfaces and dependencies between activities performed by the organization and those that are performed by other organizations.

I refer in particular to point c).  We use 3rd party suppliers, some of whom process our client data (which is stored in our datacenter), and I was wondering that if I only include the information that is stored in our datacenter in the scope, and if I don’t include 3rd parties in the scope, will the ISMS fail the audit. Or is it simply enough to say that we have controls and polices in place around the data that is stored in our data center and these controls pertain to 3rd parties and who process some of that data that resides in our datacenter.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Aug 14, 2020

You can define the scope of your ISMS as the data in the data center, but you need to state in the scope that this data is accessed by third-party, so this information can be used in the risk assessment and risk treatment process (from there you can define how to treat risks related to third-party accessing the data, normally by means of security clauses in contracts, agreements or terms of service).

These articles will provide you a further explanation about the scope definition supplier security:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Aug 14, 2020

Aug 14, 2020

Suggested Topics

Guest user Created:   Jun 30, 2016 ISO 27001 & 22301
Replies: 1
0 0

Defining the scope