Expert Advice Community

Guest

Identifying the changes in ISO 27001 scope

  Quote
Guest
Guest user Created:   Sep 11, 2020 Last commented:   Sep 11, 2020

Identifying the changes in ISO 27001 scope

My organization is certified for ISO 27001:2013.
We are planning to shift some of the on-prim applications to cloud (public cloud with virtual private cloud).
I request your help in identifying the changes in ISO 27001 scope.
What clauses and controls, I need to check at "on-prim" as well as "cloud"?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Sep 11, 2020

The definition and changes of the ISMS scope when information is on a cloud solution will depend on the control you have over the cloud

  • for IaaS, the scope excludes physical infrastructure and virtual machines
  • for PaaS, the scope excludes virtual servers, and, to some degree, applications
  • for SaaS, the scope excludes datacenter facilities’ physical location, hardware, and software

This article will provide you a further explanation about defining a scope considering cloud models:

Regarding clauses from sections 4 to 10 of the standard, the best approach would be to verify all of the one by one. Regarding controls, the proper way is by reviewing the results of risk assessment and risk treatment, and the applicable legal requirements.

The reason is that these approaches for the on-prem scope will allow you to review the current scope, and for the cloud scope all the elements are necessary for the certification.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Sep 11, 2020

Sep 11, 2020