ISO 27001

ISO 27001 · the scope statement

The ISMS scope statement, written from twelve answers

Clause 4.3 asks for the boundaries of the management system, its interfaces and dependencies with what others do for you, and the scope kept as documented information, written below from your answers with the certificate sentence first, in wording a buyer under DORA or NIS2 can check against what you actually sell.

How it is delivered
Do you have office premises?
Do staff work remotely?
Do you run infrastructure yourselves?
Do you develop the software in-house?
Is any development outsourced?
Do you process customers' personal data?

The sentence the certificate will carry

The information security management system of [company] covering the development, operation and support of [the product or service], delivered from its premises and the remote workplaces of its staff, hosted on cloud services it consumes, in accordance with the current Statement of Applicability.

A certification body prints the scope as the organisation words it; a buyer reads this sentence before anything else, and a scope that names head office but not the product is the one that fails their check.

The scope statement

# ISMS scope statement: [company]

Prepared on  with the free page on getstandardos.com against Clause 4.3 of ISO/IEC 27001:2022, considering the issues of Clause 4.1, the requirements of Clause 4.2 and the interfaces and dependencies between the organisation's own activities and those performed by others. The wording is StandardOS's own; it is a starting point to approve, not a final answer.

## Scope

The information security management system of [company] covering the development, operation and support of [the product or service], delivered from its premises and the remote workplaces of its staff, hosted on cloud services it consumes, in accordance with the current Statement of Applicability.

## Organisational boundaries

The scope covers all employees and contractors acting on behalf of [company], every team that develops, operates, supports or sells the product or service named above, and the management that directs them.

## Physical boundaries

The product or service is delivered from its premises and the remote workplaces of its staff. Each location's physical security is within the scope to the extent information or equipment of the organisation is held there.

## Technical boundaries

The production systems are hosted on cloud services it consumes; the identity, collaboration and development services the staff use are within the scope. The software is developed by the organisation's own staff; the development environment, the source code and the release process are within the scope.

## Interfaces and dependencies

The organisation depends on its hosting providers and on the identity, collaboration and software services its staff use; what each provides, the security it commits to and how it is checked are recorded in the supplier register and managed through the supplier security process.

## Personal data

Personal data of customers processed through the systems above is within the scope; the record of processing activities lists it, and the data protection obligations are treated as requirements of an interested party.

## Exclusions

None. The scope covers the whole organisation, and every Annex A control excluded is justified in the Statement of Applicability, not here.

## Issues and interested parties considered

- Customers and their auditors, who require assurance over the information entrusted to the organisation and, increasingly, the certificate itself.
- Data protection law, which governs the personal data processed and adds the supervisory authority as an interested party.
- Hosting and software suppliers, whose security the organisation depends on and cannot inspect directly.
- The organisation's own staff and contractors, whose access and awareness the controls rest on.

## Approval

Approved by: [name and title], on [date]. Reviewed at the management review and whenever the products, locations, suppliers or obligations change.

This scope statement is written from the answers given. It is not legal or certification advice; the certification body confirms the scope at the audit, and the wording on the certificate is the one it prints.
Next: the risk register

StandardOS keeps the scope with the system it bounds

The scope statement is the first document StandardOS writes from your answers, and it stays attached to the risk register, the Statement of Applicability and the supplier register that follow, so a change of product, location or supplier changes the scope with it.

Why a certificate that says head office does not cover your SaaSThe Statement of Applicability