Expert Advice Community

Guest

How much of Partial scope is permitted?

  Quote
Guest
Guest post Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

How much of Partial scope is permitted?

In the context where the "Organisation" is a part of larger organisation, there are few clarifications needed: 1. e.g. a Data centre within an Engg. Organisation. A large no of PCs are connected to the Data Centre. The Data centre hosts all the servers and the applications for an ERP. The application is used by a large no of client PCs located within the same premises or outside on leased lines. (Private network) or may be even on the internet through HTTPS. Scenerio 1: Browser based access on the client PC Scenerio 2: Agent loaded on each PC. Then only you can access the application. Scemerio 3: The IT dept. is responsible for pushing the OS updates, application updates at the client end, Virus updates as well as monitors the various other softwares running on the PCs available in the company. (That is their role is not for DC only but maintenance of all the PCs in the company). Scenerio 4: The larger Engg. company has 3 diffrent deptts. One Which runs the DC; 2nd which provides the connectivity to various usesrs/ group of users within the same premises or acro ss various locations in the country and outside. The levels of such users outside the physical premises of the comany may vary from e.g. to a regional office (with say 50 users each) to a sales office (with say only one or few PCs). 2. While the IT dept. is responsible for the maintenance of complete IT infra. including the DC and the client workstations, they want scope to be restricted to DC only excluding the network (LAN/WAN support). Is it allowed. 3. While the scope is partial is is primarily restriced to IT services, The key decion makers and resource providers are outside the IT Deptt. e.g. CEO of the organisation, Fininancial Heard, HR Head, Security Head, Utilities Head etc. 4.Is it true that ISMS Scope and the Certification Scope may be diffrent that too when the organisaion is part of a larger company. In this case, the role of a certification auditor will be confined to see the ISMS within their scope of certification. Who will the external parties (Outside the scope of certification or outside the scope of ISMS as defined by the organsaion).
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
DejanK Jan 12, 2016

Rakesh,

If I understood well, only your items #2 and #4 contain questions, so here are the answers:
2) Yes, it is allowed to restrict ISMS scope to IT services only and to exclude the network.
4) Theoretically, the company could agree with the certification body that the certification scope is narrower then the ISMS scope - however, such an arrangement is extremely rare, and it brings numerous problems (e.g. to which scope do the controls from the Statement of Applicability apply). The certification auditor does not audit external parties - the auditor must check how an organization manages the security of information related to third parties.

In any case, setting the scope which is smaller than the whole organization creates numerous problems, and it should be avoided - the best would be to have the ISMS scope that covers the whole organization. See also: Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/

Quote
0 0
Guest
Guest post Jan 12, 2016

Thankyou Sir. Is it true that, With the change of scope, the interested parties (External and internal) and the issues (external and internal) will also change. If yes, should we fix the scope first (clause 4.3) or the interested parties and the issues (4.1 and 4.2)

Quote
0 0
Guest
DejanK Jan 12, 2016

You should identify the interested parties and the issues first, because interested parties may directly influence the scope itself - e.g. some of the government agencies may require you to implement ISMS in your whole company.

See also this article: How to identify interested parties according to ISO 27001 and ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-identify-interested-parties-according-to-iso-27001-and-iso-22301//

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics

Guest user Created:   Oct 21, 2023 ISO 27001 & 22301
Replies: 1
0 0

Exclusions of the ISMS scope

Guest user Created:   Oct 06, 2023 ISO 27001 & 22301
Replies: 1
0 0

Certification scope