GlossaryISO 27001

ISMS scope

Short answer

The ISMS scope defines which parts of an organisation are covered by its information security management system: the business units, locations, processes, systems and services. In ISO 27001 it must be documented and is stated on the certificate, so customers can see exactly what is certified.

What it includes

The organisational units, locations, products and services, processes, information, technology and people inside the boundary, and the interfaces with what lies outside it, such as other departments, cloud providers and outsourced services. A typical SaaS company scopes the platform, the teams that build and run it, and supporting functions such as HR and IT.

How it is defined

ISO 27001 requires the scope to take into account the internal and external issues facing the organisation, the requirements of interested parties such as customers and regulators, and the dependencies on activities performed by others (clause 4.3). It must be available as documented information, and the auditor reviews it at stage 1.

Too narrow, too broad

A scope limited to a small team or a single office makes certification easier, but customers who read the certificate may find that the service they buy is not covered. A scope that tries to include everything from the start can stall the project. The right scope covers what customers and contracts actually care about, and it can grow over time.

How it connects

The scope frames the asset inventory, the risk assessment and the Statement of Applicability. Under the ENS, the equivalent is the set of information systems covered by the declaration or certification of conformity. Our article on what a certification audit actually tests explains how auditors check it.

Related terms

Keep reading on this topic

ISO 27001 information security management: scope, risk treatment, Annex A controls, internal audit and the certification audit process, explained.

Go to the topic hub