SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Scope. ISO 27001

  Quote
Created:   May 30, 2023 Last commented:   May 31, 2023

Scope. ISO 27001

Good afternoon. Our holding consists of several companies, there are production companies, management companies, mining companies. Our management company has an ISO 27001 certificate. The information security policy applies to all companies of the Holding. How do we format the scope correctly so that it includes all of our companies?

Tags: scope
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 31, 2023

To include all your companies in the management company certification you need to include the processes and locations of the other companies that will be part of the certification.

Please note that this approach requires that all entities will have to go through a re-certification process together.

Adopting a single certificate for all entities or separate ones for each entity is a business decision, depending on their objectives and strategies, but in general, organizations adopt the model of one certification for each entity, because a change in an entity does not impact the certification of other entities.

These articles will provide you with a further explanation of the scope definition:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 30, 2023

May 31, 2023

Suggested Topics

Bills Created:   Aug 15, 2022 ISO 27001 & 22301
Replies: 6
0 0

ISMS Scope Extension

Guest user Created:   Feb 28, 2022 ISO 27001 & 22301
Replies: 1
0 0

Clause 4.3: ISMS scope