GuideScope & Governance

Defining Your ISMS Scope Without Overcomplicating It

How to set a practical, auditable scope that covers your real business without trying to boil the ocean.

Updated 10 Mar 2026

Why Scope Matters

Your ISMS scope defines the boundary of your certification. Get it wrong and you'll either certify too little (leaving gaps auditors will question) or too much (creating unnecessary overhead).

Practical Approach

Start with your core business processes. Ask: what services, teams, and locations handle sensitive information?

Step-by-step

1List your core services — what do customers actually buy from you?
2Identify supporting processes — HR, IT, finance, development
3Map locations — offices, data centres, remote workers
4Define exclusions clearly — if you exclude something, document why

What Auditors Expect

Auditors want to see that your scope:

Reflects reality (not a sanitised version)
Covers all relevant interested parties
Includes clear justifications for any exclusions
Aligns with your Statement of Applicability

Common Pitfalls

Making scope too narrow to avoid work — auditors see through this
Including everything without resources to manage it
Forgetting remote workers or cloud infrastructure
Not revisiting scope as the business changes

Key Clauses

Clause 4.3 — Determining the scope of the ISMS
Clause 4.1 — Understanding the organisation and its context
Clause 4.2 — Understanding interested parties

Related Modules

Standard Controls
Documents

Related Controls / Clauses

4.3
4.1
4.2

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.