ISMS scope definition
Assign topic to the user
Answer: Theoretically you can, but in terms of added value this may not be the most effective way because the most sensitive business information will be probably left outside of this scope, since information also exists and flows outside information systems, and the IT department cannot be responsible for the information it doesn't own or control.
Besides that, when considering small and mid-sized business, the costs and effort involved to limit the scope very often will be higher then implementing the ISMS in the whole company.
This article will provide you further explanation about ISMS scope definition:
- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/
These materials will also help you regarding ISMS scope definition:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
Comment as guest or Sign in
Feb 20, 2017