Skip to main content
Informationssicherheit / NIS2

ISMS scope

The scope defines which organisational units, sites, processes, services and systems the information security management system covers – and which interfaces exist to the areas left outside it.

The scope sets the boundaries and applicability of an information security management system (ISMS). Clause 4.3 of ISO/IEC 27001 requires an organisation to determine these boundaries on the basis of three inputs: the external and internal issues identified under clause 4.1, the requirements of interested parties under clause 4.2, and the interfaces and dependencies between its own activities and those performed by other organisations. The scope has to be available as documented information, making it one of the few documents the standard demands explicitly.

A scope statement is usually described along several dimensions: organisational units and roles, physical sites and data centres, business processes and services, and the information, applications and networks used to deliver them. A scope may deliberately be narrow – for example the operation of a single SaaS platform at one location. What matters then is a clean description of the interfaces: where central IT, HR or data centre operations are provided from outside the scope, those services must be governed through policies, contracts and supplier management. It is important to distinguish scope from the Statement of Applicability: exclusions there concern individual Annex A controls, whereas the management system requirements in clauses 4 to 10 cannot be excluded at all.

The scope is also the commercially most sensitive part of a certification project. It is printed verbatim on the certificate, drives audit effort and cost, and determines whether the evidence a customer receives actually covers the service they bought. Certification bodies therefore challenge wording that would mislead the market, for instance when customer-facing processes are artificially carved out. In the German BSI IT-Grundschutz methodology the equivalent concept is the "Informationsverbund" defined in BSI Standard 200-2. For regulatory duties such as the NIS2 Directive and its national transposition, no certificate is required, but the security measures must cover all network and information systems used for the services concerned – so an overly narrow ISMS scope leaves a gap between certificate and legal obligation. The scope should be reviewed regularly, in particular after acquisitions, outsourcing decisions or new locations.

Legal Basis

ISO/IEC 27001:2022 clause 4.3 (in conjunction with clauses 4.1, 4.2 and 6.1.3 d); BSI Standard 200-2 (information domain)

Practical Example

A cloud provider with 200 employees pursues ISO 27001 certification because major clients demand it in tenders. The information security officer initially drafts the scope as "development and operation of the customer platform at the Cologne site", excluding sales, marketing and the second location. Analysing the interfaces reveals two problems: second-level support staff at the excluded site access production data, and HR runs the onboarding and offboarding process for all administrators. Both areas are therefore pulled into the scope, while the external data centre stays outside but is governed through processing and security agreements plus annual evidence reviews. The final scope statement, the reasoning behind each boundary and an overview of interfaces are approved and presented to the auditor as documented information.

FAQ

It names the organisational units, sites, business processes and services covered, together with the information and systems used to deliver them. It also describes the interfaces and dependencies to areas outside the scope and to external service providers. ISO/IEC 27001 clause 4.3 requires the scope to be available as documented information.
Yes – the scope does not have to cover the entire organisation. Exclusions must be justified in a comprehensible way and the remaining interfaces must be controlled. The management system requirements in clauses 4 to 10 can never be excluded; only individual Annex A controls may be left out, with justification recorded in the Statement of Applicability.
The scope appears on the ISO 27001 certificate and defines what the evidence actually covers. It also drives audit duration and cost. Certification bodies reject wording that would mislead customers, for example when central services are carved out artificially.

How preeco supports you

Learn how our software supports you with this topic.

Learn more