Govern & Assure

ISO 27001 Scoping

ISO 27001 scoping to define the boundaries of your ISMS, clarify what needs to be included, and establish a practical basis for implementation and certification.

  • A clearly defined ISMS scope
  • Clear scope boundaries
  • Alignment with the certification objective
  • Stakeholder and responsibility clarity
  • A stronger basis for gap and risk assessment

A poorly defined ISMS scope creates problems throughout an ISO 27001 programme. Include too much and you can create unnecessary work. Define it too narrowly and you risk excluding systems, services, people, or dependencies that materially affect the information security objectives you are trying to manage.

We help you establish a clear and defensible scope for the Information Security Management System before the wider implementation or certification work gets too far underway.

That means understanding the organisation, the services and information that matter, the locations and technology involved, relevant dependencies, and the reason you are pursuing ISO 27001 in the first place. We also consider the people who will need to own or contribute to the ISMS so the scope works operationally, not just on paper.

The result is a clearer starting point for the rest of the programme. Once the scope is understood, gap analysis, risk assessment, control selection, policy development, and implementation can be carried out against the right part of the organisation.

Get a quote for ISO 27001 Scoping

Tell us your scope and objectives, and we’ll come back with a clear, fixed proposal, usually the same working day.

Get a Quoteor call +44 (0) 203 393 7795
  • CREST-accredited
  • UK-based specialists
  • Crown Commercial Service supplier

How it works

  1. 01

    Understand the objective

    We start with why you are pursuing ISO 27001, what you want certification to cover, and any customer, contractual, or business requirements influencing the scope.

  2. 02

    Understand the organisation

    We review the relevant business services, teams, locations, technology, and information that could reasonably fall within the ISMS.

  3. 03

    Identify boundaries and dependencies

    We consider internal and external dependencies, supporting services, and interfaces that may affect how the ISMS needs to be defined.

  4. 04

    Agree the ISMS scope

    We work with you to establish a practical scope that reflects the organisation and the intended certification objective.

  5. 05

    Document the scope statement

    You receive the scope statement, interested-party register, and initial applicability view, ready for gap analysis.

  6. 06

    Clarify responsibilities

    We identify the key stakeholders, likely ownership areas, and the people who will need to contribute to the wider programme.

  7. 07

    Define the next step

    Once scope is agreed, we help determine whether the next activity should be a gap assessment, risk assessment, implementation work, or another part of the ISO 27001 programme.

Get the boundary right before you build the ISMS

ISO 27001 is not simply a policy-writing exercise. The ISMS needs to reflect the organisation it is intended to manage, including the risks, controls, governance, and ongoing activities within that boundary.

Getting scope right early gives the rest of the programme a firmer basis. It helps avoid reviewing controls that are not genuinely relevant, reduces ambiguity over ownership, and makes later gap assessment and implementation work more focused.

It also gives you a clearer conversation with the independent certification body when the time comes, because the intended certification scope has already been thought through rather than assembled at the end of the project.

What you get

A clearly defined ISMS scope

A practical statement of what the ISMS covers, including the relevant organisational boundaries, services, and operating context.

Clear scope boundaries

A better understanding of what sits inside and outside the ISMS, including important interfaces and dependencies.

Alignment with the certification objective

We make sure the proposed scope reflects what you are actually trying to achieve, whether that is customer assurance, tender requirements, or broader information security governance.

Stakeholder and responsibility clarity

We identify the people and functions that will need to contribute to the ISMS, helping avoid ownership gaps later in the programme.

A stronger basis for gap and risk assessment

Future assessment and implementation work can be focused on the agreed scope rather than reviewing the wrong parts of the organisation.

Practical next steps

You finish with a clear view of what should happen next, whether that is gap analysis, risk assessment, implementation planning, or preparation for certification.

Frequently asked questions

Straight answers to what prospective clients ask us most.

Do we need to define the scope before a gap assessment?

Usually, yes. A gap assessment is only useful if everyone understands which part of the organisation is being assessed.

If the scope is already clear, we can work from it. If it is uncertain, a short scoping exercise first will normally make the gap assessment more focused and useful.

Can the whole organisation be in scope?

Yes, but it does not have to be. The appropriate scope depends on what you are trying to protect and what you want the ISMS and certification to cover. For some organisations, a whole-business scope is sensible. For others, a defined service, business unit, or operating environment may be more appropriate.

Can we exclude parts of the organisation?

Potentially, where the boundary is legitimate and the resulting scope still makes sense in the context of the services, information, and dependencies involved.

The aim is not to make the scope as small as possible. It is to make it accurate and defensible.

What information do you need from us?

Typically we need to understand your organisational structure, services, locations, technology, key information, dependencies, and the reason you are pursuing ISO 27001. We will also need input from the people who understand how those areas actually operate.

Does scoping tell us whether we are compliant?

No. Scoping establishes what the ISMS should cover. It does not assess whether the requirements of ISO 27001 are currently being met. That comes through later activities such as gap assessment, risk assessment, and implementation review.

Does Blackfoot issue the ISO 27001 certificate?

No. Blackfoot can help scope, assess, implement, and prepare the ISMS, but the certification decision is made independently by an accredited certification body.

Ready to talk about iso 27001 scoping?

Get a fixed-scope quote, usually the same working day.