Skip to content

ISO 27001 scope and context

Define your ISMS through services, information, locations and dependencies. A useful scope explains what you manage and where its boundaries lie.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Run the ISO 27001 readiness scan

An ISMS scope identifies the part of an organisation covered by its information security management system. A company name or server inventory rarely explains that boundary well enough. Readers need to understand the services, information and work involved. ISO/IEC 27001 sets requirements for an ISMS. The approach below is a practical working method, not a mandatory scope template.

Start with the service you need to protect

Describe what you deliver, who receives it and which information it uses. Follow a customer request from intake to completion. List the teams, locations, applications and suppliers involved. This reveals dependencies that an IT-only description can miss: HR may trigger account changes, procurement sets supplier agreements and support handles customer information.

Record boundaries and interfaces

ElementScope questionUseful record
ServicesWhich activities will be assessed?A specific service description.
People and locationsWho performs the work and where?Teams, workplaces and responsibilities.
InformationWhat is received, processed and retained?Information flows and relevant systems.
External dependenciesWhich work is performed elsewhere?Supplier, agreement, check and contact.

Fictional example: a SaaS service

A fictional company wants certification for its customer portal. A cloud supplier hosts the portal and support staff can administer customer accounts. Describing the scope only as “production servers” would hide the influence of support and access management. A stronger working statement covers development, operation and support of the portal and explains its interfaces with hosting and HR. The cloud supplier remains external, while the dependency still needs management.

Challenge exclusions before approving them

For every proposed boundary, record why it is reasonable. Can an excluded department grant access to in-scope information? Does an unnamed location provide essential support? Leaving an activity outside a certificate description does not eliminate those risks. Discuss uncertain boundaries with the process owner and, for certification, the chosen certification body. Keep the decision and its supporting explanation together.

A worksheet for approval and changes

  1. Draft a scope statement with an owner, version and service description.
  2. Add the interfaces and dependencies that affect the service.
  3. Compare the statement with customer expectations and relevant obligations.
  4. Check that the risk assessment uses the same boundaries.
  5. Identify who reviews changes when a service, supplier or location changes.

Before using a certificate in sales material, check its actual scope. ISO’s certification guidance distinguishes standards from external certification. A limited service scope should not be presented as coverage of every activity performed by the company.

Primary sources for this topic

Frequently asked questions

Can the scope cover only one product?
A bounded product or service scope can be useful when its boundaries are clear and defensible. Include the supporting processes and dependencies that influence information security. A product name alone does not explain those interfaces. Discuss the intended certificate wording with the certification body and avoid later marketing claims that imply wider coverage than the assessed scope.
Must suppliers be covered by the same certificate?
A supplier can be relevant to your ISMS without being part of your organisation or certificate. Explain the service you obtain, the information involved and who manages agreements and checks. Outsourcing changes who performs the work; it does not make the dependency disappear. Include that dependency when defining scope and assessing information security risk.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)