Hello,
in the Scope Webinar it is said that software cannot be a scope, but a department can be.
And what about a service? In our case, it is software support service, which we offer to our clients. Can it be the scope?
Or in that case we have to formulate the scope as a department who performs the software support service?
Thank you!
Assign topic to the user
Service also cannot be defined as the ISMS scope, but your assumption is correct, you can define the department the performs the software support service as the ISMS scope. Alternatively, you can define the processes related to the software support service as the ISMS scope.
These articles will provide you a further explanation about the scope definition:
- How to define the ISMS scope https://advisera.com/27001academy/knowledgebase/how-to-define-the-isms-scope/
- Problems with defining the scope in ISO 27001 https://advisera.com/27001academy/blog/2010/06/29/problems-with-defining-the-scope-in-iso-27001/
These materials will also help you regarding scope definition:
- How to set the ISMS scope according to ISO 27001 [free webinar on demand] https://advisera.com/27001academy/webinar/how-to-set-the-isms-scope-according-to-iso-27001-free-webinar-on-demand/
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
Comment as guest or Sign in
Jul 03, 2020