An ISMS scope identifies the part of an organisation covered by its information security management system. A company name or server inventory rarely explains that boundary well enough. Readers need to understand the services, information and work involved. ISO/IEC 27001 sets requirements for an ISMS. The approach below is a practical working method, not a mandatory scope template.
Start with the service you need to protect
Describe what you deliver, who receives it and which information it uses. Follow a customer request from intake to completion. List the teams, locations, applications and suppliers involved. This reveals dependencies that an IT-only description can miss: HR may trigger account changes, procurement sets supplier agreements and support handles customer information.
Record boundaries and interfaces
| Element | Scope question | Useful record |
|---|---|---|
| Services | Which activities will be assessed? | A specific service description. |
| People and locations | Who performs the work and where? | Teams, workplaces and responsibilities. |
| Information | What is received, processed and retained? | Information flows and relevant systems. |
| External dependencies | Which work is performed elsewhere? | Supplier, agreement, check and contact. |
Fictional example: a SaaS service
A fictional company wants certification for its customer portal. A cloud supplier hosts the portal and support staff can administer customer accounts. Describing the scope only as “production servers” would hide the influence of support and access management. A stronger working statement covers development, operation and support of the portal and explains its interfaces with hosting and HR. The cloud supplier remains external, while the dependency still needs management.
Challenge exclusions before approving them
For every proposed boundary, record why it is reasonable. Can an excluded department grant access to in-scope information? Does an unnamed location provide essential support? Leaving an activity outside a certificate description does not eliminate those risks. Discuss uncertain boundaries with the process owner and, for certification, the chosen certification body. Keep the decision and its supporting explanation together.
A worksheet for approval and changes
- Draft a scope statement with an owner, version and service description.
- Add the interfaces and dependencies that affect the service.
- Compare the statement with customer expectations and relevant obligations.
- Check that the risk assessment uses the same boundaries.
- Identify who reviews changes when a service, supplier or location changes.
Before using a certificate in sales material, check its actual scope. ISO’s certification guidance distinguishes standards from external certification. A limited service scope should not be presented as coverage of every activity performed by the company.