Expert Advice Community

Guest

ISMS scope for a Hospital

  Quote
Guest
Guest user Created:   Oct 13, 2016 Last commented:   Oct 13, 2016

ISMS scope for a Hospital

How to identify the scope at hospital environment? is it possible if we choose the "security management of patient data" for isms?
0 0

Assign topic to the user

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

Guest
Antonio Jose Segovia Oct 13, 2016

Answer:
If you can protect the patient data, you can include it in your scope, but you can also identify what areas, processes, information systems, etc. that are related to this information, For example, the information is stored in a server? Human Resources area has information about employees involved in the treatment of information?

Basically you should define the scope as information, systems, processes, areas, etc. but not in terms of controls.

This article can help you “How to define the ISMS scope” : https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/

And to avoid problems defining the scope, this article can be also interesting for you “Problems with defining the scope in ISO 27001” : https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/

Finally, these materials will help you to know more about the scope:
- free online training I SO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
- book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Oct 13, 2016

Oct 13, 2016