Expert Advice Community

Guest

Scope definition considering network infrastructure

  Quote
Guest
Guest user Created:   Aug 19, 2017 Last commented:   Aug 19, 2017

Scope definition considering network infrastructure

my organisation (acme incorp) has two separate networks. one for internal use only and one for shared use between us and a major customer (but we host the network). I am not looking to get iso 27001 certification for my organisation (acme incorp), I am looking for certification for our external network which is a requirement for the contract between us and the customer. I taught, if I could tell the customer our external network is iso 27001 certified, that will give us a competitive advantage for contract renewal when the time come. Am not sure if my explanation is clear. Can I certified a network as so post to a company?
0 0

Assign topic to the user

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

ISO 27001 ISMS SCOPE DOCUMENT

Define the boundaries of ISMS for ISO 27001.

Expert
Rhand Leal Aug 19, 2017

Answer: Yes, you can include in the scope of a ISO 27001 certification only part of your infrastructure (in this case the network you share with your customer). An ISO 27001 scope can be defined in terms of processes, information or locations.

But it is important your organization evaluates if this division will not cause more administrative effort then considering including the whole organization in the scope. This is so because ISO 27001 also requires that the scope interfaces also can be identified and managed, and if your internal and external networks share a significant number of resources or contact points, maybe it won't be worth to treat them separately.

These articles will provide you further explanation about scope definition:
- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/

These materials will also help you regarding scope definition:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Aug 19, 2017

Aug 19, 2017

Suggested Topics

Guest user Created:   Jun 23, 2021 ISO 27001 & 22301
Replies: 1
0 1

ISMS implementation

Guest user Created:   Mar 10, 2021 ISO 27001 & 22301
Replies: 1
0 0

27001 ISMS Scope Question