SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Defining the scope of ISO 27001

  Quote
Guest
Guest user Created:   Aug 24, 2018 Last commented:   Aug 24, 2018

Defining the scope of ISO 27001

We are working to become ISO 27001 compliant. Please suggest how should I define the scope of ISO 27001 ?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic Aug 24, 2018

Answer: For a smaller company of up to 50 employees the best is to include your whole company into the ISO 27001 scope, because it would be too costly to try to keep a part of such small company out of the scope.

For larger companies (e.g. more than 500 employees) you should choose a department or a location to include in the scope for the beginning - after you successfully implement the standard in such smaller scope, then you can expand further.

For companies between 50 and 500 employees - you should assess which approach between the two described better fits you.

Here are some articles that will help you:
- How to define the ISMS scope: https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the ISMS scope: https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/ -defining-the-scope-in-iso-27001/

This free online training will also help you with scoping: ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Aug 24, 2018

Aug 24, 2018