ISO 27001 practical guide

ISO 27001 Scope Examples

A useful ISO 27001 scope identifies the business activities, services, organizational units, locations, technology and interfaces included in the ISMS. It should be specific enough for people and auditors to understand responsibility boundaries without disguising dependencies or excluding inconvenient risk.

Search intent
Draft a clear ISMS scope using realistic organizational examples.
Guide area
Implementation
Review status
Practitioner reviewed

What this means in practice

A scope statement is the concise result of analysis, not a substitute for boundary maps and dependency records. Include outsourced activities and interfaces where they affect outcomes, even when another party operates them.

Certification scope and internal ISMS boundaries should align with actual responsibility and communication. Confirm wording with the selected certification body when preparing for certification.

Step-by-step implementation

  1. Step 1. Identify products, services and business outcomes the ISMS protects.
  2. Step 2. Map entities, teams, locations, applications, infrastructure and information flows.
  3. Step 3. Identify suppliers, shared services and interfaces that influence security.
  4. Step 4. Decide boundaries using context, interested-party needs and accountability.
  5. Step 5. Draft concise scope wording and retain supporting boundary detail.
  6. Step 6. Test the scope against real incidents, changes, customer commitments and audit samples.
  7. Step 7. Approve and review after material organizational or technology change.

What to prepare

  • organization and service maps
  • legal entities and locations
  • application and cloud inventories
  • information flows and supplier dependencies
  • customer, regulatory and certification expectations

Documents, records and evidence

Area or fieldExampleWhy it matters
SaaS companyDevelopment, operation and support of the hosted platform; named corporate functions and cloud environmentsIncludes cloud-provider interface and remote workforce
HospitalClinical information services supporting named facilities and shared technologyMaps clinical systems, sites, third parties and medical-device interfaces
ConsultancyDelivery and support of specified advisory services from listed offices and approved remote locationsIncludes client-data platforms and subcontractors
Multi-site enterpriseCentral services plus defined business units and sitesExplains shared controls and local responsibilities
Managed service providerProvision of named managed services and supporting service platformsDefines customer/shared-responsibility interfaces

Poor and improved wording

Poor: “The IT department.” Improved: “The people, processes and technology used to develop, operate and support the Acme hosted analytics service, including the Dubai office, approved remote work, production cloud environment and managed infrastructure-provider interfaces.” Validate every element against reality.

What an auditor will look for

  • Boundaries supported by context and interested-party analysis.
  • Interfaces, outsourced processes and shared responsibilities.
  • Consistency between statement, diagrams, risk assessment and control evidence.
  • Review after acquisitions, new sites, services or architecture change.

An auditor may select different samples or follow unexpected evidence. Prepare authoritative records and owners who can explain normal operation, exceptions and improvement rather than rehearsed answers.

Common mistakes

  • Defining only a department with no service or information boundary.
  • Excluding cloud or suppliers because they are outsourced.
  • Using vague “all operations” wording that owners cannot apply.
  • Changing certification wording without updating risk and evidence scope.

Practical checklist

  • □ Services and business activities are identifiable.
  • □ Entities, teams, locations and technology boundaries are clear.
  • □ Outsourced activities and interfaces are mapped.
  • □ Supporting scope evidence matches the statement.
  • □ Risk assessment and control evidence use the same boundaries.

Frequently asked questions

Can outsourced services be outside the scope?

Operation may be outsourced, but relevant interfaces, responsibilities and risks still need treatment within the ISMS.

Must every office be included?

Determine scope from business activities, responsibility and risk; explain included and excluded locations clearly.

How detailed should the statement be?

Concise enough to communicate publicly where needed, supported by more detailed internal boundary information.

Continue through the practical guide library

Use the topic hub to connect this task with related implementation, risk, governance, evidence and audit-preparation guidance.

Browse all ISO 27001 practical guides →