Expert Advice Community

Guest

Scope for ISO 27001

  Quote
Guest
Guest user Created:   May 05, 2020 Last commented:   May 05, 2020

Scope for ISO 27001

Our company is planning to go for ISO 27001 Certification this year. Our company is a SI and supporting, implementing enterprise-level cybersecurity projects to many sectors. As for the scope, we want to define our production network only, contains many critical system/security controls like Firewall, DNS, AD, and many more... Our boss want to say that company's production network is running with ISO 27001 standard. I wonder that that scope is acceptable or not by the auditor.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 05, 2020

The ISMS scope can cover all organization, or only specific locations, processes, or information.

The main point when considering this approach is the effort required to keep the ISMS scope separated from the rest of the organization's elements (for small and mid-sized organizations many times the effort is not worthy, and it is better to include all the organization in the ISMS scope)

These articles will provide you a further explanation about the scope definition:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 05, 2020

May 05, 2020