ISO/IEC 27001 and 27000 both allow organizations to define the scope of the ISMS according to their needs, including the entire organization, specific departments, business units, or locations.
" The scope of the ISMS can be as broad or narrow as the organization chooses, so long as boundaries are clearly defined and justified. "
— ISO/IEC 27001:2022, Clause 4.3
— ISO/IEC 27000:2018, Section 2.2
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit