Exclusions from the ISMS scope
Assign topic to the user
How can I do it? Should I define this in the scope document as an exclusion or maybe I should not mention it at all (I mean that I will only mention a department which works with the serviceA in the „Organizational Units“ section)? I understand that I will have to assess the risks that the serviceB may cause and I will mitigate them with some policy (Acceptable Use, Access Control) and also some technical controls.
Also a similar situation could be like this: a department consists of 10 employe es. Only two of them work with the serviceA (which is in scope). Can I include only those two? And how to do that? What exactly should be defined in the „Exlusions from the scope“ section of the ISMS Scope Document? Is it something that we cannot control but it affects the security? What I want to emphasize by asking this is why should we define exclusions – maybe we do not need to exclude anything since it is not included in the scope?
Answer:
You should only use the "Exclusions from the scope" section to explicitly define elements that are inside your statement of scope but you do not want the ISMS to handle them. If you can make this separation when defining the scope, there is no need to define exclusions.
A good example is your department scenario. You can define only the two roles that have access service A as part of the ISMS scope (in this case there are no exclusions), or you can define your department as a whole inside the ISMS scope and include the roles that do not need access service A as "Exclusions from the scope".
Considering your other scenario, if service B is completely unrelated to, or can be easily separated from, service A, there is no need to mention service B as "Exclusion from the scope". On the other hand, if service B is part of service A, then you should include service B on "Exclusions from the scope" so your ISMS does not need to manage it.
On both cases, to keep the document as simple as possible we suggest you to make the necessary separation when defining the scope.
It is important to note that exclusions may mean an extra cost and effort to keep the separation from the elements in the scope, and in some cases it may be better to include all elements in the ISMS scope.
These articles will provide you further explanation about scope definition:
- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/
Comment as guest or Sign in
Mar 19, 2019