Skip to content

Scope

Defining the ISMS scope: narrow enough to start, complete enough for the audit

A scope is not a marketing phrase. It has to delimit services, organisational units, sites, technology and interfaces consistently.

Back to ISO 27001

8 minute read · Content as of 21.07.2026

Start from the service, not from the org chart

A sound scope first describes which products or services are protected. From that follow the necessary processes, information, applications, systems, suppliers and sites.

A purely organisational boundary often overlooks shared platforms and central service providers. Exactly these interfaces will lead to follow-up questions in the audit later.

Every boundary needs a justification

Excluded areas are not automatically unproblematic. If an excluded service affects the scope, the dependency has to be managed. Therefore document not only what is included, but also the relevant handovers to the outside.

  • Services and customer commitments
  • Organisational units and roles
  • Sites and working models
  • Information types, applications and infrastructure
  • External services and intra-group dependencies

The free scope canvas delivers the first draft

Use the canvas from the template library for a moderated 60-minute session. The result is not yet an approved scope statement, but a robust working basis for the context analysis and the asset inventory.

Sources used

Back to ISO 27001