ISO 27000 Foundation Certification Scope of the ISMS 5 — Questions and Answers
Question 1: Which scenario demonstrates an inappropriate ISMS scope exclusion?
- Excluding a cafeteria management system with no access to sensitive data
- Excluding an e-commerce platform that processes customer payment information (Correct answer)
- Excluding a physical gym facility used only by staff
- Excluding a legacy system already decommissioned
Correct answer: Excluding an e-commerce platform that processes customer payment information
Excluding an e-commerce platform that processes payment data is inappropriate because it handles sensitive information that falls under the organization's security obligations.
Question 2: What is the consequence if an organization's ISMS scope is too broad?
- Certification is automatically granted for all areas
- Implementation becomes resource-intensive and may be ineffective across the entire scope (Correct answer)
- The risk register can be simplified
- External audits become shorter
Correct answer: Implementation becomes resource-intensive and may be ineffective across the entire scope
A scope that is too broad can stretch resources thin, leading to superficial control implementation that may not effectively manage risks across all covered areas.
Question 3: How does the concept of 'interfaces and dependencies' affect ISMS scope decisions?
- It determines the number of ISO controls to implement
- It ensures that relationships with out-of-scope entities are considered so security gaps are not created at boundaries (Correct answer)
- It mandates that all third parties be brought within the ISMS scope
- It applies only to cloud service dependencies
Correct answer: It ensures that relationships with out-of-scope entities are considered so security gaps are not created at boundaries
Identifying interfaces and dependencies helps the organization understand how out-of-scope activities can create security risks at the boundaries of the ISMS.
Question 4: A company's ISMS scope includes 'information in all formats.' What does this imply?
- Only digital data stored on servers is covered
- Physical documents, verbal communications, and digital data are all within scope (Correct answer)
- Printed materials are always excluded from ISMS controls
- Only structured database records are included
Correct answer: Physical documents, verbal communications, and digital data are all within scope
When scope includes 'information in all formats,' it encompasses digital, physical (paper), and other forms of information, ensuring comprehensive protection.
Question 5: Which stakeholder group has the MOST influence on determining the initial ISMS scope?
- IT helpdesk staff
- Top management (Correct answer)
- External auditors
- Vendors and suppliers
Correct answer: Top management
Top management is responsible for ensuring the ISMS aligns with organizational strategy and objectives, making them the most influential stakeholder in scope decisions.
Question 6: An organization operating in both healthcare and retail decides to certify only its healthcare division under ISO 27001. This is an example of:
- Non-compliance with ISO 27001 requirements
- Defining ISMS scope by business unit or division (Correct answer)
- Applying controls selectively without justification
- Mandatory industry-specific scoping
Correct answer: Defining ISMS scope by business unit or division
Scoping the ISMS to a specific business division is a legitimate and common approach, provided the scope boundaries and any exclusions are properly documented.
Question 7: Which of the following best ensures that an ISMS scope remains valid over time?
- Locking the scope document and preventing changes after certification
- Regularly reviewing scope as part of management reviews and internal audits (Correct answer)
- Asking the certification body to approve all scope changes in advance
- Limiting scope reviews to once every three years
Correct answer: Regularly reviewing scope as part of management reviews and internal audits
Regular management reviews and internal audits provide formal mechanisms to reassess and update the ISMS scope as the organization and its context change.
Which scenario demonstrates an inappropriate ISMS scope exclusion?