What falls within scope?
Overview of ISO 27001 requirements
One of the first requirements for ISO 27001 is defining the scope, meaning what entities will be covered by the ISMS (Information Security Management System). It defines which systems, services, information, policies, functions, and geographies will be covered in the ISO 27001 scoping document and, hence, protected by the ISMS.
The scope document is of utmost importance considering it’s directly presented to stakeholders, investors, partners, and customers.
You’ll have the opportunity to write your own scope statement for the certification, so aim to keep it clear and concise, ideally within a single paragraph.
The scope document is of utmost importance considering it’s directly presented to stakeholders, investors, partners, and customers.
You’ll have the opportunity to write your own scope statement for the certification, so aim to keep it clear and concise, ideally within a single paragraph.
ISO 27001 Scope Statement: Ultimate Guide
ISO 27001 Series
Basics
Certification Process
Policies & Management
Risk Management
Resources & Templates
Sprinto: Your ally for all things compliance, risk, governance