Scope
Defining the ISMS scope: narrow enough to start, complete enough for the audit
A scope is not a marketing phrase. It has to delimit services, organisational units, sites, technology and interfaces consistently.
8 minute read · Content as of 21.07.2026
Start from the service, not from the org chart
A sound scope first describes which products or services are protected. From that follow the necessary processes, information, applications, systems, suppliers and sites.
A purely organisational boundary often overlooks shared platforms and central service providers. Exactly these interfaces will lead to follow-up questions in the audit later.
Every boundary needs a justification
Excluded areas are not automatically unproblematic. If an excluded service affects the scope, the dependency has to be managed. Therefore document not only what is included, but also the relevant handovers to the outside.
- Services and customer commitments
- Organisational units and roles
- Sites and working models
- Information types, applications and infrastructure
- External services and intra-group dependencies
The free scope canvas delivers the first draft
Use the canvas from the template library for a moderated 60-minute session. The result is not yet an approved scope statement, but a robust working basis for the context analysis and the asset inventory.
Sources used
- ISO/IEC 27001:2022 · ISO · 2022 + Amd 1:2024
- ISO/IEC 27002:2022 · ISO · 2022
- ISMS practice patterns · KaitoSec