ISO 27000 Foundation Certification Scope of the ISMS 4 — Questions and Answers
Question 1: Which ISO 27001 clause specifically requires the organization to determine the scope of the ISMS?
- Clause 5 – Leadership
- Clause 4 – Context of the organization (Correct answer)
- Clause 6 – Planning
- Clause 8 – Operation
Correct answer: Clause 4 – Context of the organization
Clause 4.3 of ISO 27001 explicitly requires the organization to determine the boundaries and applicability of the ISMS to establish its scope.
Question 2: A software firm includes its development team in the ISMS scope but excludes the sales team. Customer contracts handled by sales contain sensitive data. What should the firm do?
- Extend the scope to include sales or implement compensating controls for customer data handled by sales (Correct answer)
- Keep the scope unchanged since sales is a non-technical function
- Instruct sales staff to follow informal security guidelines
- Transfer all customer data handling to the development team
Correct answer: Extend the scope to include sales or implement compensating controls for customer data handled by sales
When sensitive data is processed outside the ISMS scope, the organization must either expand the scope or ensure equivalent controls exist for that data.
Question 3: In the PDCA (Plan-Do-Check-Act) cycle applied to the ISMS, at which stage is the scope initially established?
- Do
- Check
- Act
- Plan (Correct answer)
Correct answer: Plan
ISMS scope is established during the Plan stage, along with risk assessment, objectives, and the selection of controls.
Question 4: An organization reviews its ISMS scope annually and expands it to include a newly acquired subsidiary. What does this reflect?
- A failure to define scope correctly at the outset
- Continual improvement and adaptation of the ISMS to changing organizational context (Correct answer)
- A violation of ISO 27001 scope stability requirements
- An unnecessary increase in certification costs
Correct answer: Continual improvement and adaptation of the ISMS to changing organizational context
Updating the ISMS scope in response to organizational changes reflects the continual improvement principle central to ISO 27001.
Question 5: Which of the following is an example of an internal issue that could influence ISMS scope?
- New data privacy legislation in a target market
- A competitor launching a new product
- The organization's culture and existing security maturity (Correct answer)
- A government cybersecurity advisory
Correct answer: The organization's culture and existing security maturity
Internal issues such as organizational culture, existing security practices, and maturity levels directly influence what is feasible and appropriate to include in the ISMS scope.
Question 6: A financial services firm's ISMS scope statement reads: 'All systems supporting retail banking operations at the New York headquarters.' What type of boundary does this represent?
- Functional and physical boundary (Correct answer)
- Temporal and personnel boundary
- Vendor and supply chain boundary
- Network topology boundary only
Correct answer: Functional and physical boundary
The scope statement defines both a functional boundary (retail banking operations) and a physical boundary (New York headquarters).
Question 7: According to ISO 27001, when should the ISMS scope be reviewed?
- Only when a security incident occurs
- Whenever there are significant changes to the organization or its context (Correct answer)
- Every five years as part of the certification renewal cycle
- Only when requested by the certification body
Correct answer: Whenever there are significant changes to the organization or its context
The ISMS scope should be reviewed whenever significant organizational or contextual changes occur that may affect the boundaries or applicability of the ISMS.
Which ISO 27001 clause specifically requires the organization to determine the scope of the ISMS?