Expert Advice Community

Guest

Scope for a small company with outsourced infrastructure to mother company

  Quote
Guest
Guest user Created:   Oct 20, 2017 Last commented:   Oct 20, 2017

Scope for a small company with outsourced infrastructure to mother company

We are 9 employees service company and a part of mother company. all our asset (IT hardware, network and applications) belong to our mother company. Employees are employed by the mother company or outsourced by the third party. our company is a contract partner with the B2B customers as we are a service provider to our mother company. We contract with the customer on services which are provided by our mother company.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic Oct 20, 2017

Thus, we customer acquire the customer's, contact with them on own name but on behalf of our mother company. Data and customer information is saved in the databases and the portal which belongs to the other company. CRM system which we process is also not ours.

However, our management has initiated ISO 27001 certification for our service company. I have selected the scope for ISO 27001 certification a business process.

During the webinar you told me that it is very hard to get the certification if the business process will be certified.

Answer:

For a small company such as yours it is very difficult to lim it the scope of the implementation and certification to only one process - this is because once you define what is inside the ISMS scope, all other processes and activities that are left outside of the scope will be treated as external (third) parties. Therefore, for a company of 9 employees, the best would be to include your whole company in the ISMS scope.

See also this article: Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/

The fact that your company is not an owner of the equipment or services that you are providing doesn't change much - your company is responsible for the data because it is the contractual party with your clients. Therefore, you are responsible for safeguarding data even though this data is not placed on your servers. The fact that the processing is done by your mother company doesn't make much difference - the principle is the same as if you hosted this data on e.g. Amazon AWS, in other words you need to treat your mother company as a provider of services, i.e. as a third-party.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Oct 20, 2017

Oct 20, 2017

Suggested Topics

Guest user Created:   Oct 21, 2023 ISO 27001 & 22301
Replies: 1
0 0

Exclusions of the ISMS scope

Guest user Created:   Oct 06, 2023 ISO 27001 & 22301
Replies: 1
0 0

Certification scope