Identifying the changes in ISO 27001 scope
My organization is certified for ISO 27001:2013.
We are planning to shift some of the on-prim applications to cloud (public cloud with virtual private cloud).
I request your help in identifying the changes in ISO 27001 scope.
What clauses and controls, I need to check at "on-prim" as well as "cloud"?
Assign topic to the user
The definition and changes of the ISMS scope when information is on a cloud solution will depend on the control you have over the cloud
- for IaaS, the scope excludes physical infrastructure and virtual machines
- for PaaS, the scope excludes virtual servers, and, to some degree, applications
- for SaaS, the scope excludes datacenter facilities’ physical location, hardware, and software
This article will provide you a further explanation about defining a scope considering cloud models:
- Defining the ISMS scope if the servers are in the cloud https://advisera.com/27001academy/blog/2017/05/22/defining-the-isms-scope-if-the-servers-are-in-the-cloud/
Regarding clauses from sections 4 to 10 of the standard, the best approach would be to verify all of the one by one. Regarding controls, the proper way is by reviewing the results of risk assessment and risk treatment, and the applicable legal requirements.
The reason is that these approaches for the on-prem scope will allow you to review the current scope, and for the cloud scope all the elements are necessary for the certification.
Comment as guest or Sign in
Sep 11, 2020