ClausePass27001 Toolkit 2.0 is available
See what is included in the current toolkit release.
View pricingLoading page…
Scope and governance
Your scope statement is one sentence, but teams disagree about the systems, suppliers, and locations behind it.
The short answer
Do not start by polishing the scope sentence. Draw the service and follow the information through people, systems, locations, and suppliers. Record every boundary choice and interface. Write the formal scope only when another person can reconstruct what is in, what is out, and who accepted the consequences.
Published by ClausePass2700112 minute readUpdated 2026-09-04Part of the free 134-page implementation manual
Instant PDF. No email or account required.
A usable ISMS scope states where the management system applies and where its boundary ends. It should let another practitioner follow how an in-scope service is delivered, which information and activities are involved, what technology and locations support it, and where responsibility crosses into another team, legal entity, system, or provider.
Draft the formal sentence after tracing the service. Beginning with elegant wording often hides the interfaces that matter most. Keep the scope statement concise, then use the maintained context and scope register for detailed paths, reasons, conditions, and ownership.
Current operation and planned expansion must remain distinguishable. A proposed platform, future location, or expected acquisition may influence present risk decisions, but it should not be described as though it already operates.
Record an internal or external issue when it can change an ISMS decision, intended result, resource need, or operating design. Give each issue a destination and a reconsideration trigger.
At this guide's source-check date, ISO/IEC 27001:2022/Amd 1:2024 applied to the requirements edition. Consult the licensed standard and amendment when considering climate change in the organization's context and interested-party work. Do not paste a generic climate sentence into the register; preserve the organization's supported determination and its source.
A category such as customers, regulators, or suppliers is too broad to operate. Identify the particular class and the source that gives its requirement force.
| Field | Decision-safe content |
|---|---|
| Party | The individual, organization, or defined class whose requirement is being considered. |
| Source | The contract class, law, regulation, service commitment, group instruction, or other current authority. |
| Requirement | A concise account suitable for making a decision, without pretending the register created the interpretation. |
| Interpretation owner | The competent and authorized person or function responsible for the interpretation. |
| Affected subject | The service, information, process, control, record, interface, or claim changed by the requirement. |
| ISMS route | How the organization has decided to address it through the management system. |
| Review trigger | The date, source change, service change, dispute, or other event that reopens the entry. |
| Open condition | Any conflict, missing fact, or limit that prevents an unconditional decision. |
Legal, regulatory, and contractual interpretation must come from a competent, authorized source. The ISMS register preserves the result and its lineage; it does not create the interpretation.
Write a short proposition stating the service result, who relies on it, the information handled, the main activities, and the accountable authority. Then test it against current evidence.
At each crossing, record enough information for an operator to know what should happen and for a reviewer to reconstruct responsibility.
A central function can perform one in-scope activity and several out-of-scope activities. An out-of-scope function can still be essential to an in-scope service. Record the applicability of each material activity, the authority that can change it, the responsibilities crossing the boundary, and the trigger for reconsideration.
The same applies to providers. State what the provider performs and what the organization retains, such as selection, configuration, access, monitoring, incident response, or contractual oversight. Avoid language claiming control of a provider's entire environment. Preserve conflicts between contracts, architecture, and observed practice until an authorized decision resolves them.
The statement should make each decision below possible without private explanation from its author.
| Scope dimension | What must be decidable |
|---|---|
| Service | Which delivered services the ISMS governs. |
| Organization and activity | Which organizational elements and operating activities participate. |
| Place | Which physical and virtual locations are included. |
| Technology | Which environments support the governed service. |
| Exclusions | What is outside, why, and whether that treatment remains supportable. |
| Interfaces and dependencies | Where responsibility, information, or operation crosses the boundary. |
| Authority | Which version is approved and which events trigger review. |
Mark the statement provisional when a disputed responsibility, supplier assumption, or service definition could materially change it.
A RACI chart can support governance, but it cannot replace a description of what each authority may decide, who acts during absence, and where the decision is retained.
| Decision family | Authority to make explicit |
|---|---|
| Direction | Purpose, scope, policy, objectives, resources, and external claims. |
| Risk | Method and criteria, risk ownership, acceptance, treatment, and control change. |
| Controlled direction | Policies, standards, procedures, exceptions, waivers, and superseded material. |
| Obligations | Who can provide or approve legal, regulatory, contractual, and sector interpretation. |
| Operation and evidence | Who accepts operating results, evidence conclusions, and exceptions. |
| Assurance | Audit program approval, conflict controls, finding response, and follow-up. |
| Management review | Who evaluates the ISMS and commits resources or directs change. |
| Certification | Whether and when to pursue certification and who controls related claims. |
Test one consequential decision under inconvenient conditions: an absent authority, disagreement, provider delay, urgent change, or incomplete evidence. Confirm that the deputy and escalation route work.
Give participants the source record before the meeting and show where evidence conflicts. A presentation without a maintained decision is not approval.
The scope does not need ornamental wording. It needs current sources, owned requirements, traceable service and information paths, explicit applicability decisions, visible interfaces, separated provider responsibilities, tested authorities, and owned review triggers. Risk assessment should receive the approved boundary together with every material obligation and open assumption.
This chapter is ClausePass27001 implementation guidance. It does not reproduce the standard, decide conformity, or replace competent legal, technical, audit, or certification advice. Check the current authorized sources before relying on a version-sensitive point.