ISO/IEC 27001 and 27000 both allow organizations to define the scope of the ISMS according to their needs, including the entire organization, specific departments, business units, or locations.
"The scope of the ISMS can be as broad or narrow as the organization chooses, so long as boundaries are clearly defined and justified."
— ISO/IEC 27001:2022, Clause 4.3
— ISO/IEC 27000:2018, Section 2.2
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit