Why Scope Matters
Your ISMS scope defines the boundary of your certification. Get it wrong and you'll either certify too little (leaving gaps auditors will question) or too much (creating unnecessary overhead).
Practical Approach
Start with your core business processes. Ask: what services, teams, and locations handle sensitive information?
Step-by-step
1List your core services — what do customers actually buy from you?
2Identify supporting processes — HR, IT, finance, development
3Map locations — offices, data centres, remote workers
4Define exclusions clearly — if you exclude something, document why
What Auditors Expect
Auditors want to see that your scope:
•Reflects reality (not a sanitised version)
•Covers all relevant interested parties
•Includes clear justifications for any exclusions
•Aligns with your Statement of Applicability
Common Pitfalls
•Making scope too narrow to avoid work — auditors see through this
•Including everything without resources to manage it
•Forgetting remote workers or cloud infrastructure
•Not revisiting scope as the business changes
Key Clauses
•Clause 4.3 — Determining the scope of the ISMS
•Clause 4.1 — Understanding the organisation and its context
•Clause 4.2 — Understanding interested parties