Step 1 · Set the scope

ISMS scope What your management system covers.

The scope defines which sites, organisational units, services and interfaces belong to your management system. Everything else builds on it.

What it is about

ISO/IEC 27001 clause 4.3 requires you to determine the boundaries and applicability of the ISMS and keep them as documented information. The basis is the context of the organisation (4.1), the requirements of interested parties (4.2) and the interfaces with activities performed by others. Under NIS2 you cannot cut the scope freely: the measures under Section 30 BSIG apply to the systems, components and processes you use to provide your services.

Step 1Set the scope
  • SectorEnergy
  • Employees480
  • Annual turnover€95m
  • NIS2selected
  • ISO 27001selected
  • AI Actselected
  • CRAnot selected

Sample values

How to go about it

  1. 01

    Collect the internal and external issues that affect your information security.

  2. 02

    Record interested parties and their requirements: customers, authorities, insurers, parent company.

  3. 03

    Define sites, units, services and interfaces, and justify exclusions.

  4. 04

    Have management approve the scope and update it when things change.

Common mistakes

  • The scope is so narrow that critical services are missing.
  • Interfaces with service providers and cloud services are not described.
  • Exclusions appear without justification.

What an auditor wants to see

  • Documented scope with version and approval
  • List of interested parties and their requirements
  • Overview of interfaces and dependencies

How UniqSuite helps

UniqSuite records company, sector, size, the selected frameworks and the people responsible, and produces a scope report as PDF, Word or Excel. The following steps show the requirements of the selected frameworks.

References

  • ISO/IEC 27001, clauses 4.1 to 4.3
  • ISO/IEC 27001, clause 5.3: roles and responsibilities
  • Section 30(1) BSIG

Frequently asked questions

Can the scope cover only part of the company?

For ISO 27001, yes, if the boundaries are clearly described and justified. The legal obligations under NIS2 do not depend on it, though.

When is the scope reviewed?

With every significant change, such as new sites, services or providers, and at the latest in the management review.

What about outsourced processes?

They remain your responsibility. ISO 27001 clause 8.1 requires externally provided processes, products and services that are relevant to the ISMS to be controlled. Describe the interface with the provider in the scope.

Why does the scope matter for the risk assessment?

The risk assessment, the Statement of Applicability and internal audits all refer to the defined scope. Anything outside it is neither assessed nor audited.

Does an AI management system under ISO 42001 need its own scope?

Yes. ISO/IEC 42001 clause 4.3 also requires you to determine the scope. It may overlap with the ISMS, but it is determined and documented separately.

See what this looks like in UniqSuite.

In half an hour we walk you through it with your own questions.

→Demo request

Show us your questions.

We will get back to you within two working days and arrange a demo of about 30 minutes – built around your own requirements.

Please fill in.

Please fill in.

Please fill in.

Please enter a valid email address.

Please use digits, spaces and + ( ) / - only.

We use your details solely to answer your request. Details in our privacy policy.