Scope
Last checked on
On Scope you record what falls inside your management system, what you leave out and why, and where your responsibility ends and another party's begins. You then establish it as a fixed version.
Why this protects your organisation
A customer who reads your certificate wants to know what it actually covers. If the scope is vague, you either end up protecting everything to the same level, which is expensive, or you promise more than you deliver. A clear scope also tells your team which systems and locations the agreed measures apply to. ISO 27001 clause 4.3 asks you to define these boundaries and keep them documented.
Steps
- Open Scope in the Organisation group.
- Click Start drafting the scope. If a scope has already been established, click Start a new version instead.
- Describe the activities, locations and systems under What falls inside the scope of your management system?
- Under What falls outside the scope, and why, click Add an exclusion and fill in What is excluded and Why.
- Describe the Boundaries with other parties, such as a hosting provider or a shared platform, and click Save.
- Once the text is agreed, click Establish and confirm.
Nothing is written just by opening this page. You start a draft explicitly, save it as often as you like, and establish it when it is ready.
The fields
- What falls inside the scope of your management system? The activities, locations and systems that are covered. For example the application you sell, the infrastructure it runs on and the offices your team works from.
- What falls outside the scope, and why Anything a reader might assume is included but is not, each with its reason. A sales office that never touches customer data is a typical example.
- Boundaries with other parties Where your responsibility stops and someone else's starts. A cloud provider that runs your servers is a common case: you manage your configuration, they manage the data centre.
Versions
When you click Establish, the draft becomes the established scope, with your name and the date. From then on it cannot be edited. A change goes into a new version, so you can always show which scope applied at a given time.
When you adopt a standard, you can choose the established scope as the scope of that adoption.
If it does not work
I cannot change the established scope
An established version is read only. Click Start a new version to open a draft. The established version stays visible above it until you establish the new one.
I do not see Start drafting the scope, Save or Establish
These buttons only appear for people who may edit the scope: owners, members, and advisors with edit rights for the Organisation module.
Saving fails on an exclusion
Each exclusion needs both What is excluded and Why. Fill in both, or remove the empty exclusion.
Screens this is about
- Scope