Expanding ISMS scope
Assign topic to the user
1) should they implement ISO 27001 to the whole organisation?
2) or should they implement to others division or department?
Answer: Both strategies for implementing the ISMS on other parts of the organization are valid, but you also should consider the deadline expected to achieve the full implementation, the complexity of the other processes and the resources available to recommend one or another. Considering that any implementation project adds a great deal of stress in the organization, you preferably should suggest them to go for implementing the ISMS to the whole organization.
3) It is a separate ISMS implementation or they can extend the current ISMS implementation through out the organisation?
Answer: You can make an extension of your current ISMS implementation to include the new departmen ts. You only have to take care to include the new departments in the scope presented to the certification body only when they are prepared to undergo a certification audit, since for the certification body this addition to the scope will have to undergo all the steps of a certification audit.
Comment as guest or Sign in
Mar 24, 2017