Skip to main content
Category: ISMS Clauses and Planning

ISMS Scope

Also known as: Scope of the ISMS, ISO 27001 Scope, Information Security Management System Scope, Scope Statement
Simply put

The ISMS scope defines which parts of an organization are covered by its Information Security Management System under ISO/IEC 27001. It sets the boundaries by identifying the processes, information assets, locations, and technologies that are included, along with anything that is deliberately left out. In short, it draws the line around what the security management system is responsible for protecting.

Formal definition

The ISMS scope is the formally documented boundary of the Information Security Management System, required under ISO/IEC 27001 Clause 4.3 (Determining the scope of the information security management system). It specifies the organizational units, processes, information assets, locations, and technologies covered by the ISMS, and typically documents any exclusions with justification. The scope must be aligned with actual business operations, as it establishes the boundaries within which ISMS activities and controls apply and against which certification is assessed. Because an ISO 27001 certificate covers only the defined ISMS scope, controls, activities, or assets outside that boundary are not covered by the certification. Scope determination is informed by the organization's context and interested parties (Clauses 4.1 and 4.2) and, in most implementations, feeds into the selection of Annex A reference controls via the Statement of Applicability.

Why it matters

The ISMS scope is one of the most consequential decisions an organization makes when pursuing ISO/IEC 27001 certification, because it determines exactly what the certificate covers. An ISO 27001 certificate attests only to the defined scope of the Information Security Management System; controls, activities, locations, or assets that fall outside that documented boundary are not covered by the certification. This means that two organizations holding valid ISO 27001 certificates may have protected very different portions of their operations, so readers of a certificate need to examine the scope statement rather than assume the entire organization is covered.

Because the scope establishes the boundaries within which all ISMS activities and controls apply, and against which the certification body assesses conformity, an inaccurate or misaligned scope can undermine the credibility of the entire management system. A scope that is drawn too narrowly may exclude information assets or processes that interested parties reasonably expect to be protected, while a scope that does not reflect actual business operations can create gaps between what is documented and what is practiced. Under ISO/IEC 27001 Clause 4.3, the scope must be aligned with real operations and is informed by the organization's context and interested parties as determined under Clauses 4.1 and 4.2.

The scope also has practical downstream effects: in most implementations it feeds into the selection of Annex A reference controls through the Statement of Applicability. Getting the scope wrong, or leaving exclusions undocumented and unjustified, can therefore ripple through control selection, risk assessment, and audit outcomes, potentially delaying or complicating certification.

Who it's relevant to

Compliance and GRC Managers
Compliance managers responsible for pursuing or maintaining ISO 27001 certification must define and document the ISMS scope under Clause 4.3, ensuring it is clear, justified, and aligned with actual business operations. They are typically accountable for keeping the scope statement accurate as the organization changes and for documenting any exclusions with justification.
ISO 27001 Auditors and Certification Bodies
Auditors assess conformity of the ISMS against the defined scope, and the certification they support covers only that documented boundary. A clear, operationally aligned scope allows them to evaluate whether controls and activities within the boundary meet the standard's requirements.
Security Engineers and ISMS Implementers
Those implementing the ISMS need the scope to understand which processes, information assets, locations, and technologies fall within the boundary. In most implementations the scope feeds into the selection of Annex A reference controls via the Statement of Applicability, shaping where controls are applied.
Customers and Interested Parties Reviewing a Certificate
Prospective customers, partners, and other interested parties reviewing an ISO 27001 certificate should examine the scope statement rather than assume the whole organization is covered. Because the certificate attests only to the defined scope, understanding what is included, and what is deliberately excluded, is essential to interpreting the certification correctly.

Inside ISMS Scope

Scope Statement
A defined boundary describing the parts of the organization, information assets, processes, and services covered by the Information Security Management System (ISMS). This scope determines what the ISO/IEC 27001 certificate applies to and appears on the certificate itself.
Organizational Boundaries
The business units, functions, teams, or legal entities included within the ISMS. Depending on scope, an organization may certify a single product line, a specific site, or the entire enterprise.
Physical and Logical Boundaries
The locations, facilities, systems, networks, and technology environments encompassed by the ISMS, along with any interfaces or dependencies on parties outside the scope that must be identified and managed.
Interfaces and Dependencies
The connections between activities performed within the ISMS and those performed by external parties or excluded functions. ISO/IEC 27001 requires that these interfaces and dependencies be considered when determining the boundaries.
Justification for Exclusions
Where parts of the organization or its activities are excluded, the rationale for those exclusions is documented so that the scope remains defensible and clear to the certification body and interested parties.
Relationship to Clause Requirements
Determining the ISMS scope is addressed within clauses 4 through 10 of ISO/IEC 27001 (the certifiable ISMS requirements), and the scope informs the risk assessment and the Statement of Applicability used to select Annex A reference controls.

Common questions

Answers to the questions practitioners most commonly ask about ISMS Scope.

Does defining an ISMS scope mean the entire organization is covered by the ISO 27001 certificate?
No. The ISO 27001 certificate covers only the defined scope of the ISMS, not necessarily the whole organization. The scope is set by the organization and may be limited to particular business units, locations, services, or systems. Anything outside the documented scope is not addressed by the certification, so readers of a certificate should check the scope statement to understand what is actually covered.
Is the ISMS scope the same thing as the Statement of Applicability?
No, they are distinct. The ISMS scope defines the boundaries and applicability of the management system and is addressed under the clause 4 requirements. The Statement of Applicability is a separate document that records which Annex A reference controls are applicable, justifies inclusions and exclusions, and is informed by the risk assessment. The scope shapes what the ISMS covers, while the Statement of Applicability documents control selection within that context.
How do you decide what to include in the ISMS scope?
Scope decisions typically consider the organization's context, interested parties and their requirements, the interfaces and dependencies between activities performed by the organization and those performed by others, and the products or services in question. In most implementations, teams weigh which functions, locations, and systems are relevant to the information security objectives. The specifics depend on the organization and how it interprets the clause 4 requirements.
Can third-party or outsourced services be excluded from the ISMS scope?
The scope must account for interfaces and dependencies with activities carried out by other parties, so outsourced services cannot simply be ignored if they affect information within the ISMS. Depending on scope, an organization may address these through defined boundaries and controls over the interfaces rather than including the third party's operations directly. How this is handled varies by organization and should be justified clearly.
How should the ISMS scope be documented?
The scope is typically maintained as documented information, describing the boundaries and applicability of the ISMS. In most engagements this includes the covered activities, locations, and systems, along with any relevant exclusions and their justification. The exact format and level of detail vary based on the organization and the expectations of the certification body.
What happens if the organization changes after the scope is defined?
The ISMS scope is expected to be reviewed and kept current as the organization, its context, or its interested parties change. If new services, locations, or dependencies fall within the intended coverage, the scope may need to be updated, which can also affect risk assessment and control selection. Because the certificate covers only the defined scope, keeping it accurate matters for what the certification represents.

Common misconceptions

An ISO 27001 certificate always covers the entire organization.
A certificate covers only the defined scope of the ISMS. This may be a single site, product, or business unit rather than the whole enterprise, so the scope statement should be reviewed to understand what is actually covered.
The ISMS scope is the same concept as a SOC 2 report's scope, so the two are interchangeable.
ISO/IEC 27001 certification against an ISMS scope and a SOC 2 attestation examination are distinct. A SOC 2 report attests to controls over a period against selected Trust Services Criteria, while an ISO 27001 certificate covers the defined ISMS scope. Mapping between the two is possible but partial, and one does not automatically satisfy the other.
A narrower scope means a weaker or less legitimate ISMS.
Scope is a deliberate decision, not a measure of quality. A tightly defined scope can be entirely appropriate depending on the organization's objectives, provided the boundaries, interfaces, and any exclusions are justified and clearly documented.

Best practices

Document the scope statement clearly, identifying the organizational, physical, and logical boundaries so that interested parties and the certification body can understand exactly what the ISMS covers.
Identify and consider all interfaces and dependencies with functions or parties outside the scope, as required when determining ISMS boundaries.
Document a justification for any exclusions so the defined scope remains defensible during certification and surveillance activities.
Ensure the scope aligns with and informs the risk assessment and the Statement of Applicability used to select Annex A reference controls.
Review the scope periodically and when the organization changes, since additions to sites, services, or business units may fall outside the currently certified boundary.
Communicate the boundaries of certification internally and to customers, clarifying that the certificate covers only the defined ISMS scope and does not extend to functions or systems outside it.