Expert Advice Community

Guest

ISMS scope for a cloud provider

  Quote
Guest
Guest user Created:   Apr 27, 2016 Last commented:   Apr 27, 2016

ISMS scope for a cloud provider

My company is a cloud provider with Infrastructure as a service (IaaS) model. In simple terms we rent servers, networks and security appliances to our customers. We keep the hardware and underlying infrastructure running, and our customers upload their data to the servers and control who has access to it.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
Antonio Jose Segovia Apr 27, 2016

My question is about defining the ISMS Scope. As a service provider, how do we set the scope for ISMS ?

Since we “hand control” of the servers to our customers and they have control over what data is uploaded and who can access it, I am struggling to see how that can be included in the scope.

Answer:
From my point of view, to set the scope for your ISMS, you can focus it on the information that you can manage: information about customers, financial information, information about providers, information about your employees, about your systems, etc. Maybe you have a CRM and/or an ERP, and you can also include it in your ISMS scope, because these applications have information. Keep in mind that ISO 27001 is about the protection o f information.

For more detail about the scope, please read this article “How to define the ISMS scope” : https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/

And our online course can be also interesting for you, because we give more information about the ISMS scope “ISO 27001:2013 Foundations Course” : https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 27, 2016

Apr 27, 2016

Suggested Topics

Guest user Created:   Jun 23, 2021 ISO 27001 & 22301
Replies: 1
0 1

ISMS implementation

Guest user Created:   Jan 24, 2020 ISO 27001 & 22301
Replies: 1
0 1

ISMS Scope

Guest user Created:   Jun 28, 2017 ISO 27001 & 22301
Replies: 1
0 0

Scope and asset definition