SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Question on ISMS scope definition

  Quote
Guest
Guest user Created:   Mar 03, 2021 Last commented:   Mar 03, 2021

Question on ISMS scope definition

Thanks so much for the webinar. We were finalizing our scope and our management wanted us to consider a smaller scope. Can you just remind me on a couple of points you made in the webinar?


1 - The scope cannot be a server or a product, because it is a management standard right? Does this then mean that it can’t be an environment, like a cloud environment? Would you set the scope as the software engineering department for example instead?

2 - And you mentioned the scope cannot be drawn between people who share the same office? Does this mean they would also need to be segregated in terms of network or email environment?

I’d really appreciate your opinion as I think the delivery time will be quite different if we chose the smaller scope rather than the whole company, although maybe more detailed in segregating them.

1 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 03, 2021

1 - The scope cannot be a server or a product, because it is a management standard right? Does this then mean that it can’t be an environment, like a cloud environment? Would you set the scope as the software engineering department for example instead?

Your assumption is correct. The ISMS scope cannot be defined in terms of products, assets, or technologies. It needs to be defined in terms of information, location or processes to be protected, so the definition of the scope as a software engineering department is more appropriated.

This article will provide you a further explanation about scope definition:

These materials will also help you regarding scope definition:

2 - And you mentioned the scope cannot be drawn between people who share the same office? Does this mean they would also need to be segregated in terms of network or email environment?
I’d really appreciate your opinion as I think the delivery time will be quite different if we chose the smaller scope rather than the whole company, although maybe more detailed in segregating them.

Please note that, for small environments, it is better to define all its elements as the ISMS scope because the effort and costs to segregate them may not be worthy, compared to managing all elements as part of the ISMS scope.

This article will provide you a further explanation about scope definition:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 03, 2021

Mar 03, 2021

Suggested Topics