ISO 27000 Foundation Certification Scope of the ISMS 2 — Questions and Answers
Question 1: Which document formally records the boundaries and applicability of an organization's ISMS?
- Risk register
- Statement of Applicability
- Scope statement (Correct answer)
- Asset inventory
Correct answer: Scope statement
The ISMS scope statement is the document that formally defines the boundaries and applicability of the information security management system.
Question 2: An organization decides to exclude its HR department from the ISMS scope. What must it do according to ISO 27001?
- Justify the exclusion and ensure it does not affect security obligations (Correct answer)
- Obtain written approval from the certification body
- Apply all controls to HR anyway as a precaution
- Notify all employees of the exclusion in writing
Correct answer: Justify the exclusion and ensure it does not affect security obligations
ISO 27001 requires organizations to justify any exclusions and ensure those exclusions do not affect the ability to achieve intended outcomes or compliance obligations.
Question 3: Which of the following best describes an 'interested party' in the context of ISMS scope?
- Only internal employees who use IT systems
- Any person or organization that can affect or be affected by the ISMS (Correct answer)
- Shareholders and board members only
- External auditors and regulators exclusively
Correct answer: Any person or organization that can affect or be affected by the ISMS
Interested parties include any person or organization that can affect, be affected by, or perceive themselves to be affected by the ISMS.
Question 4: A company's ISMS scope includes its main office but not its remote data center operated by a third party. What risk does this create?
- The certification audit will automatically fail
- Information security risks from the data center may not be managed under the ISMS (Correct answer)
- The company cannot implement any controls at all
- Remote work policies become invalid
Correct answer: Information security risks from the data center may not be managed under the ISMS
Excluding a third-party data center means risks originating there are outside the ISMS framework, potentially leaving significant vulnerabilities unmanaged.
Question 5: Context of the organization, as required by ISO 27001 Clause 4, influences ISMS scope by identifying:
- The number of controls to implement
- Internal and external issues relevant to information security (Correct answer)
- The budget allocated for security tools
- The name of the ISMS manager
Correct answer: Internal and external issues relevant to information security
Clause 4 requires organizations to determine internal and external issues that are relevant to the ISMS purpose and that affect its ability to achieve intended outcomes.
Question 6: When defining ISMS scope, which factor is LEAST relevant to consider?
- Interfaces and dependencies between activities performed by the organization and those by other organizations
- The organization's branding and marketing strategy (Correct answer)
- Legal and regulatory requirements applicable to information security
- The nature of the information the organization processes
Correct answer: The organization's branding and marketing strategy
Branding and marketing strategy are business concerns that do not directly influence the boundaries of an information security management system.
Question 7: Which statement about ISMS scope documentation is correct per ISO 27001?
- The scope must be approved by an external consultant before implementation
- The scope must be available as documented information (Correct answer)
- The scope can be kept confidential and not shared with auditors
- The scope only needs to be defined at the initial certification stage
Correct answer: The scope must be available as documented information
ISO 27001 requires that the ISMS scope be maintained as documented information that is available to relevant parties.
Which document formally records the boundaries and applicability of an organization's ISMS?