Just like how a building is only as good as its foundation, your ISO 27001 certification is only as good as the scope of your Information Security Management Systems (ISMS). Writing the scope statement, therefore, is undeniably one of the most critical things you will do when you kickstart your Cumplimiento de la norma ISO 27001 journey. To experience the sustainable benefits of your certification, it is vital to define the scope comprehensively to ensure coverage of your critical products, information, software, systems, subsidiaries, services, functions, processes, and geographies that need ISO certification.
But strong foundations take work. Here’s a ‘quick and dirty’ guide on how to write an ISO 27001 scope statement that works.
TL; DR: Sprinto can help you automate the entire compliance journey & help you get ISO 27001 compliance-ready in just weeks. To write an effective scope statement for your ISO 27001 certification, it is important to understand what information your organization needs to protect and the processes, people, technology and information assets and infrastructure associated with that information. Listing exclusions, if any, is also a critical step here.
What is ISO 27001 Scope?
ISO 27001 scope defines the breadth of your Certificación ISO 27001 by the information, products, processes, services, systems, functions, subsidiaries, and geographies your organization needs to protect through its ISMS.
En el, for a SaaS platform that manages health information for pharmaceutical enterprises (let’s call it ABC, shall we?), the scope can be defined as the design, development, maintenance, technical support, sales, and marketing of ABC.
In short, ISO 27001 scope is the information your organization wants to protect through its ISMS. Information security is defined as the confidentiality, integrity, and availability of the right information, to the right people, and at the right time.

Clause 4.3 of the ISO 27001 standard discusses the nuances of how to set the scope of your ISMS. Note that a detailed Statement of Applicability would support the scope statement.
What is an ISO 27001 Scope Statement?
ISO 27001 statement appears in your ISO 27001 certificate. It’s what your customers, prospects, and other stakeholders will read and know is ISO certified as protected by your ISMS.
In the example given earlier, the ISO 27001 scope statement can be “design, development, maintenance, technical support, sales and marketing of ABC”.

Typically, the scope statement is documented as a couple of lines to a paragraph or two and will find a place in the ISO 27001 certificate. While writing your scope statement, ensure that it covers the products and/or services, and associated functions. Your customers will derive confidence in your information controles de seguridad and infosec posture by looking at your certificate. Your scope statement, therefore, mustn’t be unambiguous; it should be written as clearly as possible.
En el, a scope statement that reads “All information stored, processed and managed in the New York office….” doesn’t make much sense if the organization is headquartered in San Francisco, where most of its employees work. Does this mean information stored, processed, and managed at their headquarters isn’t safe enough?
Writing a comprehensive scope statement elicits confidence from your stakeholders, and when you don’t, it raises more than eyebrows! An incorrect or insufficient scope statement can also raise questions from the auditores de certificación.
“I loved that everything is actually connected. It’s not form-filling. Sprinto is actually checking my AWS environment for safety and security. Instead of me sharing a register of people, Sprinto simply looks at our GSuite to map and monitor risk” – Ruben Stolk, Founder and CTO, Capptions
What is ISO 27001 Scope Examples?
The ISO 27001 scope examples includes all employees, location, data assets, and technologies owned by the company. It also includes the company’s business processes employed to deliver [List the products and services in scope].
Hence, before your start writing your scope statement and ponder on what you should include, it’s important to have clarity on the following organizational aspects:
- What information does your organization need to protect?
- What are the processes that are associated with that information?
Your answers to these questions will give you a distinct overview of what needs to be included in the scope statement.
The scope statement must primarily include the products and/or services your organization is looking to certify and the associated functions, locations, systems, processes, people, and subsidiaries that support its design, development, maintenance, technical support, sales and marketing. It also includes relevant laws and regulations, and standards for information security.
More often than not, it’s the easiest to include the whole organization in the scope. From people, processes, systems, and physical locations, to products, software, and others would make it to the scope then. In our experience of having helped define the scope for hundreds of cloud-hosted organizations on their ISO journey, it’s safest to take this approach. This approach, however, makes sense for small to mid-sized organizations.
Bigger organizations, or those with specific compliance needs, can limit their scope to a dedicated part, product, process, or service. While carving out a portion of your organization for your ISO 27001 scope might seem less work, it has its pitfalls. More on that later.
Lea también: Requisitos de la norma ISO 27001
How to write an ISO 27001 2013 Scope Statement?
The ISO security standard doesn’t define guidelines on how long or short the scope statement must be. But you will do well to remember the scope should be centered on what your customers are buying from you, directly and indirectly, and, therefore, need assurance of your organization’s postura de seguridad.
You will find many articles on the internet that discuss writing detailed documents supporting your scope statement; these documents have network diagrams, lists, and whatnot. But guess what? It isn’t mandatory to have a detailed document. While you can still write one to support your scope statement, a comprehensive one is good enough.

Here’s a small checklist for writing an ISO 27001 scope statement.
- Do you know what information your organization needs to protect?
- Make a list of the products and/or services in scope.
- Line up the processes, people, technology, information assets and infrastructure that help deliver the listed products and services.
- Are there any exclusions (out-of-scope)? List the associated locations, processes, and other relevant headers that make it to the exclusion list.
Once you have the answers to these questions, you can write the statement of scope. Remember to keep it as unambiguous as possible. Define the scope such that it can grow with your organization.
What about exclusions?
If you want to narrow your scope to only a specific part of your organization, or pilot test it initially to a limited scope, here are some things you must consider:
- While a more straightforward scope may cost you less initially, it will also reduce your business benefits vis-a-vis a broader scope.
- The standard treats everything outside the ISMS scope as external and ‘untrustworthy’. So, you will need to define security interfaces for process and data flow that go beyond the scope.
But what about vendors?
It isn’t uncommon for organizations to use external or third-party vendors to deliver specific services. And some of them might be privy to information within your ISMS’s scope.
La organización gestión de riesgos de proveedores policy should be put to use in such cases. Contracts with strict SLAs, cuestionarios de seguridad, periodic audits, and reviews, to name a few, are some of the ways organizations can ensure their data is secure with their vendors.
También mira: How to hire ISO 27001 consultant
Declaración del alcance de la norma ISO 27001 Ejemplos
Let’s look at ISO 27001 scope statement examples:
Amazon Web Services Scope
Haga clic aquí to see how Amazon Web Services has listed all the products/services in its ISO 27001 scope.

Gitlab’s ISO 27001 Scope
Gitlab has included what’s excluded from its scope.

Remote organizations would have similar exclusions in their scope statements too as there wouldn’t be a physical office location.
Captions’s ISO 27001 Scope
Leyendas, a Netherlands-based EHS management software provider has a comprehensive yet short scope statement.

With Sprinto’s help, Captions secured their ISO 27001 título o certificación 3x más rápido.
What do you have to document, and where?
The statement of scope is one of the mandatory documents as per ISO 27001 standard. It can be produced as a single document or be a part of the documentation compiled for the framework. So, document the scope and make it available to the auditores internos y externos as well as the certification body.
ISO 27001 Scope Statement Template
You can’t use the many scope statement templates for your organization. As you would have realized by now, the scope is a custom definition and changes with the organization’s size, geographies, products and services, among other things.
Bigger organizations with complex offerings, such as Amazon Web Services have a different scope compared to a relatively small organization.
So, don’t fall for templates being peddled on the World Wide Web. Research and read the examples, but when you write one for your organization, make it yours.
Know more about how to set the scope of your ISMS
How can Sprinto help?
From defining the scope for your ISO 27001 certification to building your Statement of Applicability and helping you get 100% ready for an Auditoría ISO 27001, Sprinto can help you navigate the entire compliance journey with ease and confidence.
Sprinto’s automated compliance platform is built to reduce human intervention. Our intelligent continuous monitoring feature makes it easier for organizations to collect evidence, and manage the entire documentation stack for the standard.
Choose the smart way to comply. Talk to us !

Autor
Srividhya Karthik
Srividhya Karthik, jefa de contenido en Sprinto, transforma con maestría el complejo mundo del cumplimiento normativo en lecturas accesibles e interesantes. Cuenta con cinco años de experiencia en el ámbito del cumplimiento normativo, abarcando marcos como SOC 2, ISO 27001, GDPR y otros. Es una autoridad indiscutible en la materia y guía a los lectores con conocimiento y claridad.Explora más artículos sobre la norma ISO 27001.
Descripción general y requisitos de la norma ISO 27001
ISO 27001 frente a otros marcos
Proceso de auditoría y certificación ISO 27001
Gestión y evaluación según la norma ISO 27001
Implementación y automatización de la norma ISO 27001
Aplicaciones específicas de la norma ISO 27001
Investigaciones y análisis seleccionados para ayudarte a ganarte un lugar en la mesa.














