Expert Advice Community

Guest

Scoping for ISO 27001

  Quote
Guest
Guest user Created:   Jul 01, 2020 Last commented:   Jul 03, 2020

Scoping for ISO 27001

I want to ask scoping for ISO 27001 standard. I want to know that we can go ''production network" as for scope in certification, not entire network of our company.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jul 01, 2020

I'm assuming that the "production network" is a technology.

Considering that, the ISMS scope can be defined in terms of locations, business units, or processes, i.e., where the information you want to protect is stored or processed, not technologies. However, you can define the scope in terms of only the part of the organization, but in general, for small and mid-sized business, the best approach is to include the entire organization in the ISMS scope, because the effort to separate the scope for such organizations may not be worthy.

These articles will provide you a further explanation about the scope definition:

These materials will also help you regarding scope definition:

Quote
0 1
Guest
Aron Ye Jul 02, 2020

Our company is SI providing cyber security, network, virtualization, managed security service solutions to banking and other sectors. We have over 90 employees as total. We have our own internal network including critical system and security controls. We have plan to make this internal network to be ISO 27001 ISMS certified. Is this possible? can this be accepted by ISO auditor? 

Quote
0 0
Expert
Rhand Leal Jul 03, 2020

The internal network itself cannot be defined as the ISMS scope. Since the ISMS scope can be defined in terms of locations, business units, or processes, the recommended approach for your case is to define the ISMS scope in terms of the business units, or processes that manage the services and systems on this internal network.

For example: "The ISMS scope are the processes/business units related to the management and operation of the following services/systems: <describe the services/systems in this internal network>"

Quote
0 1

Comment as guest or Sign in

HTML tags are not allowed

Jul 01, 2020

Jul 03, 2020

Suggested Topics