SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

ISMS Scope Assistance

  Quote
Guest
Guest post Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

ISMS Scope Assistance

My company is contracted with a local data center to provide us with Infrastructure as a Service. The physical infrastructure that we use (firewalls, network switches, servers, and storage) is all leased from our datacenter host and they provide support of this physical infrastructure. My company's IT team builds and manages the operating system and application layers. Physical access to the equipment located at the data center is allowed to both members of my IT team as well as support personnel of the data center. In this situation, what is recommended to be included/excluded from the ISMS scope document? Thanks, Chris
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
DejanK Jan 12, 2016

If you store and process sensitive/important information for your company in that data center, then you should include such information in your ISMS scope.

In this kind of a situation, physical infrastructure should be placed out of your scope (since you do not control it directly), and you should place within the scope only what you control - operation system, applications, and of course data.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics

Guest user Created:   Jun 07, 2022 ISO 27001 & 22301
Replies: 1
0 0

ISMS scope

Guest user Created:   Sep 14, 2021 ISO 27001 & 22301
Replies: 1
0 0

Scope in Conformio

Guest user Created:   Oct 21, 2022 ISO 27001 & 22301
Replies: 1
0 0

Gap analysis results