Expert Advice Community

Guest

ISMS scope

  Quote
Guest
Guest user Created:   May 17, 2017 Last commented:   May 17, 2017

ISMS scope

I recently took on the CISO role at a software company that is interested in gaining 27001 certification for ONE of their products (which is hosted on xxxxx). Seems like we would have a limited scope, and all the controls would be relative to that software and its development?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 17, 2017

Answer: First of all, ISO 27001 cannot be used to certify products. This standard can be used to certify an organization's Information Security Management Systems, regarding processes, organizations units and locations. That said, your assumption is correct when considering that you can have a limited scope, defining your Information Security Management System in terms of the software development process used to deliver the product, as means to ensure to your customers that the required information security measures are identified, included and maintained in the software. But you should also note that limiting the scope doesn't make sense for smaller companies, since it will require greater effort than managing the security considering the whole organization.

This art icle will provide you further explanation about ISMS scope:
- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/

These materials will also help you regarding ISMS scope:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 17, 2017

May 17, 2017

Suggested Topics

Guest user Created:   Oct 21, 2023 ISO 27001 & 22301
Replies: 1
0 0

Exclusions of the ISMS scope

Guest user Created:   Dec 05, 2022 ISO 27001 & 22301
Replies: 1
0 0

ISMS scope

Guest user Created:   Oct 21, 2022 ISO 27001 & 22301
Replies: 1
0 0

ISMS scope