Expert Advice Community

Guest

ISMS scope

  Quote
Guest
Guest user Created:   Dec 05, 2022 Last commented:   Dec 05, 2022

ISMS scope

Would like to seek for your advise as below:

Scope: Provision of IT services of the Data Centre Facilities at DC1 & DC2 to the customers of ***.

Changes: DC1 going to be migrated to a rent space at DC3 in 2 years time with self remote manage all systems

                  To include Security Monitoring Centre in the scope in 2 years time

Questions:

1. Should DC1 to be excluded from the scope and when?

2. How to include systems hosted at DC3 in the Scope and under proper security control?

3. What will be the recommended scope statement due to the changes?

Let us know if any further information needed.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Dec 05, 2022

1. Should DC1 to be excluded from the scope and when?

From your question I'm understanding that only physical space will be rented.

Considering that, only physical space and its management should be excluded from the scope, by the time you move your assets to the rented space.

2. How to include systems hosted at DC3 in the Scope and under proper security control?

Since these systems (i.e., hardware and software) are already in the scope, as part of DC1, and DC3 is out of the scope, you need to state the systems in the scope, instead of the state of a data center.

3. What will be the recommended scope statement due to the changes?

An example of changed scope is:

"Provision of IT services of the Data Centre Facilities at DC2 & remote managed systems at DC 3 to the customers of ***."

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 05, 2022

Dec 05, 2022

Suggested Topics