ISO 27001 Clause 4.3 Determining the Scope of the Information Security Management System + Template

 

ISO 27001 Scope of the ISMS

In this ultimate guide to ISO 27001 Clause 4.3 Determining the Scope of the Information Security Management System, you will learn:

  • What is ISO 27001 Clause 4.3?
  • How to implement ISO 27001 Clause 4.3
  • How to define ISO 27001 Scope
  • Example ISO 27001 Scope Statements

I am Stuart Barker, the ISO 27001 Ninja and author of the Ultimate ISO 27001 Toolkit.

Using over 30 years of industry experience across hundreds of audits, I’m giving you the exact templates, walkthroughs, and practical examples you need to achieve ISO 27001 certification.

Key Takeaways

  • The scope should reflect what you want to be shown on your ISO 27001 certificate
  • Narrowing scope will remove undue cost and bureaucracy
  • Getting the scope wrong can cost a lot of time and lot of money

What is ISO 27001 Clause 4.3?

ISO 27001 Clause 4.3 Determining The Scope Of The Information Security Management System is an ISO 27001 clause that requires you to define the scope of your information security management system.

Purpose

The purpose of ISO 27001 Clause 4.3 Determining The Scope Of The Information Security Management is to ensure a clear and well-defined scope for your Information Security Management System (ISMS) and your subsequent ISO 27001 certification. This clarity helps establish:

  • Which parts of the organisation are included within the boundaries of the ISMS.
  • The specific areas that will be assessed during the ISO 27001 certification audit.

By defining the scope, you can ensure that your ISMS is focused on the most critical areas and that your certification accurately reflects the extent of your information security efforts.

Definition

The ISO 27001 standard defines ISO 27001 Clause 4.3 Determining The Scope Of The Information Security Management as:

The organization shall determine the boundaries and applicability of the information security
management system to establish its scope.
When determining this scope, the organization shall consider:
a) the external and internal issues referred to in 4.1;
b) the requirements referred to in 4.2;
c) interfaces and dependencies between activities performed by the organization, and those that are
performed by other organizations.
The scope shall be available as documented information.

ISO27001:2022 Clause 4.3 Determining The Scope Of The Information Security Management System

Context

  1. Establish scope by determining the boundaries and applicability of the information security management system: There is a cost in time, resource and money to implement ISO 27001 so it makes sense to concentrate on protecting the things that your clients are expecting to you to protect and the things that represent the biggest risk to you. I will show you how to do this later in the article.
  2. Consider your internal and external issues: When you set the scope you are making sure that you have addressed the internal and external issues that we covered in ISO 27001 Clause 4.1 Understanding the Organisation and It’s Context.
  3. Consider the needs an expectations of interested parties: The interested parties and their requirements which we covered in ISO 27001 clause 4.2 Understanding the Needs and Expectations of Interested Parties will be reviewed on if, and how, they affect the scope you are setting.
  4. Consider what you do verses what other people do for you: Third parties will be used a lot and those third parties will be responsible for the areas that they control so you will define the interfaces and dependencies between activities you do and activities that they do.
ISO 27001 Toolkit Business Edition

FREE Training Video

In this free training video I show you how to implement ISO 27001 Clause 4.3 Scope and how to pass your audit.

How to define ISO 27001 Scope

Scope is vitally important for your ISO 27001 Certification. It clearly sets out what we are going to apply our information security management system to and more importantly it defines what will go on our ISO 27001 certificate.

Determining your scope effectively can be challenging. To assist you, we’ve created a comprehensive guide: How To Define ISO 27001 Scope.This guide provides clear, step-by-step instructions to help you establish a well-defined scope.

We’ve included an ISO 27001 Scope Statement Template within our ISO 27001 Toolkit. This template can be used as a valuable resource to assist in the development of your official scope statement.

Based on practical, real world implementations and experience this is how to implement ISO 27001 Clause 4.3 Determining The Scope Of The Information Security Management System (ISMS):

Define Organisational Boundaries

Clearly identify where the organisation’s boundaries lie, especially in complex or multi-national organisations.

  • Utilise organisational charts, legal documents, and stakeholder interviews to define the organisational structure.
  • Consider third-party relationships and their impact on information security.

List all your products and services

List out all of the products and services that you have and document them.

  • Conduct workshops with key interested parties (e.g., management, product owners, sales) to identify and document core offerings.
  • Utilise process mapping and data flow diagrams to visualise the flow of products and services.

Ask your customers which products and services they expect to be in scope

From your list of products and services ask your customers which of them they expect to be in scope. Review current contracts for any scope requirements.

Ask your leadership team which products and services they expect to be in scope

From your list of products and services ask your leadership team which of them they expect to be in scope.

Ask the list of interested parties which products and services they expect to be in scope

From your list of products and services ask your interested parties which of them they expect to be in scope.

Document the list of products and services that are in scope

Taking the input from customers, leadership and interested parties document the list of products and services that are in scope.

Review your internal and external issues

Review the products and services that are in scope against the list of internal and external issues to determine if their are any direct issues or changes to issues.

Confirm the list of of products and services that are in scope

Agree and sign off the scope with the senior leadership team and document the agreement.

Identify Supporting Functions

Determine which departments and functions are critical to the delivery of core products and services.

  • Analyse organisational structure and identify departments that directly or indirectly support core business functions.
  • Consider departments like IT, HR, finance, legal, and facilities.

Determine Scope Exclusions

Identify activities, departments, or systems that will be explicitly excluded from the scope of the ISMS.

  • Clearly document the rationale for any exclusions.
  • Ensure that excluded areas do not pose significant risks to the organisation’s information security.

Document and understand the ISO 27001 Scope Boundaries

Identifying the people, premises, technology, and suppliers that directly support the in-scope products and services and understand the interfaces between in scope entities and out of scope entities as well as with third party organisations.

Write your ISO 27001 Scope Statement

Summarise your scope in the required ISO 27001 scope statement.

  • Use clear and concise language.
  • Obtain input and approval from key interested parties.
  • Regularly review and update the scope statement to reflect changes in the organisation or its environment.

Communicate Scope to Stakeholders

Ensure that all relevant stakeholders understand the scope of the ISMS and their roles and responsibilities within it.

  • Conduct training sessions and awareness campaigns.
  • Distribute the scope statement to all employees.
  • Include the scope statement in relevant policies and procedures.

Obtain Management Approval

Secure management approval for the defined scope of the ISMS.

  • Present the proposed scope to management and address any concerns or questions.
  • Obtain formal approval from top management.

Verify the scope statement with the certification body (optional)

Share your ISO 27001 scope statement with the external ISO 27001 certification body auditor for feedback and confirmation.

CEO at High Table: The Compliance Agency

How to document scope

Your scope statement is the heart of your certification. It is the text that will eventually be printed on your ISO 27001 certificate. If it is poorly documented, you risk misleading your customers or, worse, failing your Stage 1 audit because the auditor cannot identify what they are supposed to be testing.

A professionally documented scope statement must include four key elements:

  • The Legal Entity: Clearly state the name of the company or the specific business unit being certified.
  • The Services/Products: Define exactly what the ISMS protects (e.g., “The provision of cloud-based payroll services”).
  • The Physical and Logical Boundaries: Mention your primary locations and your core infrastructure (e.g., “Operating from the Leeds head office and utilizing AWS Dublin regions”).
  • The Exclusions: If you are excluding a department or a location, you must document the justification. “We just didn’t want to include them” is not a valid justification.

ISO 27001 Scope Template

The ISO 27001 Scope Template provides a structured framework for defining the scope of your Information Security Management System (ISMS), fully meeting the requirements of ISO 27001 Clause 4.3.

It was designed and built with these key features:

  • Pre-filled with common scope examples: Provides a solid foundation and saves you time.
  • Available as an individual download: Offers flexibility for specific needs.
  • Included in the internationally acclaimed ISO 27001 Toolkit: Access a comprehensive suite of templates and resources to streamline your entire implementation process.
ISO 27001 Clause 4.3 Determining the Scope of the Information Security Management System  Template

How to approve your ISO 27001 Scope

Approval is not just a signature on a page; it is the moment your leadership team accepts the risk and responsibility for the boundaries you have drawn. Under Clause 5.1 (Leadership and Commitment), top management must demonstrate they are ‘all in.’ If they haven’t formally approved the scope defined in Clause 4.3, your certification will fail at the first hurdle.

To get your scope approved correctly, follow these three non-negotiable steps:

  • The Scoping Workshop: Present the draft boundaries to the board or senior leadership. Explain exactly what is IN and what is OUT. If they don’t understand the exclusions, they can’t approve them.
  • Formal Minute Recording: Approval should happen during a Management Review Meeting or a dedicated Security Steering Group. Ensure the decision is recorded in the minutes. An auditor will ask to see these.
  • The Versioned Sign-Off: Your Scope Statement should have a version history and an approval block. I expect to see a name, a role (typically the CEO or CISO), and a date.

ISO 27001 Scope Statement Example

An example ISO 27001 Scope Statement:

The scope of this Information Security Management System (ISMS) encompasses all products and services offered by [Organisation Name], as outlined in [link to product/service catalogue or relevant document]. The implementation of controls is detailed within the Statement of Applicability, version [version number].

In practice:

A practical example, taken directly from our ISO 27001 certification, is:

Information security consultancy and virtual chief information security officer services in accordance with the statement of applicability version 2.1

High Table ISO 27001 Scope Statement
ISO 27001 Toolkit Business Edition

10 real-world ISO 27001 Scope Statement examples

To help you draft your own documented information, here are 10 examples of scope statements across various industries. Remember, clarity is the priority.

  1. Software as a Service (SaaS): “The scope of the ISMS includes the development, maintenance, and hosting of the [Product Name] platform, including all customer data stored within the AWS Production Environment.”
  2. Professional Services: “Provision of legal and consultancy services, including all supporting IT infrastructure and physical offices located at [Address].”
  3. Managed Service Provider (MSP): “Management and monitoring of client infrastructure, including the helpdesk operations, remote management tools, and onsite support staff.”
  4. FinTech Startup: “The ISMS encompasses the [App Name] mobile application, the underlying API architecture, and the payment processing gateway interfaces.”
  5. E-commerce: “Security of the online retail platform, including the checkout process, warehouse management systems, and customer database.”
  6. Healthcare Provider: “Protection of patient records and diagnostic data within the [System Name], including all medical devices connected to the internal hospital network.”
  7. Manufacturing: “The ISMS covers the design and production of [Product], specifically protecting the intellectual property on the CAD servers and the PLC controllers on the factory floor.”
  8. Education: “The administration of student records and the delivery of online learning modules via the University Virtual Learning Environment (VLE).”
  9. AI Development: “The lifecycle of AI model training, including data ingestion pipelines, GPU compute clusters, and the proprietary algorithm repository.”
  10. HR & Payroll Outsourcing: “Processing of employee payroll data and benefits administration, including the secure transfer of data to HMRC and third-party pension providers.”

How to legally de-scope to reduce audit costs

One of the biggest secrets in ISO 27001 implementation is that a smaller scope usually leads to a more effective system and a significantly lower audit fee. As a Lead Auditor, I see many organisations pay for five days of auditing when they only needed three. Strategic de-scoping is the art of removing non-critical business units without compromising your security posture.

Lead Auditor Rules for De-scoping

You can legally exclude parts of your organisation if you can prove to me that they do not impact the security of the primary in-scope assets. Use these three strategies to lean out your ISMS:

De-scoping Strategy How it Works Business Benefit
Departmental Exclusion Exclude non-technical departments (e.g. Facilities or Marketing) if they do not handle sensitive client data. Reduces the number of staff interviews required during the audit.
Geographic Exclusion Only scope the primary headquarters or data centre. Exclude small satellite offices. Eliminates the cost of physical site inspections for minor locations.
Product Segregation Certification of only one specific high-risk platform rather than the whole company. Provides the “ISO 27001 Badge” for your main revenue generator at a fraction of the cost.

Why Climate Change matters for ISO 27001 Clause 4.3

As an ISO 27001 Lead Auditor, I see too many organisations treating Clause 4.3 as a “set and forget” exercise. That is a mistake that will lead to a minor non-conformity in your next audit. Following the February 2024 Amendment 1, you are now mandated to consider climate change when determining your scope.

If your Clause 4.1 context identifies climate risks but your Clause 4.3 scope statement ignores them, your Management System is disconnected. You cannot claim to have an effective ISMS if the boundaries of your security do not account for the very real physical and transition risks posed by a changing climate.

The standard now requires you to determine if climate change is a relevant issue. If it is, that relevance must flow directly into your scope. You are defining the “where” and the “what” of your security. If your “where” is a flood zone or an area with an unstable power grid due to extreme heat, your scope must reflect that reality.

Strategic Impact of Climate Change on ISMS Boundaries

Climate FactorImpact on Clause 4.3 ScopeAuditor’s Expectation
Physical Risk (Flooding/Fire)Mandatory inclusion of specific geographic locations or data centres in high risk zones.I want to see that your “Premises” boundary includes the specific physical protections for those sites.
Resource Scarcity (Power/Water)Scope must extend to include backup power systems and cooling infrastructure for server rooms.You cannot exclude “Facilities Management” from your scope if climate change threatens your server uptime.
Supply Chain VolatilityExpanded “Interface” boundaries to include alternative SaaS or hosting providers in different regions.Your scope statement must acknowledge the dependencies on third parties that are themselves at risk.
Regulatory ShiftsInclusion of “Legal and Regulatory Compliance” as a primary driver for the ISMS boundary.If new green laws require data residency changes, your scope must adjust to those new territories.

How to Update Your Scope for Amendment 1

To pass your audit, you must demonstrate that you have performed a “Climate Sanity Check” on your boundaries. Use the following list to verify your Clause 4.3 documentation is compliant.

  • Review your Clause 4.1 Output: Look at the internal and external issues you identified regarding climate.
  • Identify Geographic Vulnerabilities: If you have shifted to “Remote First” because your main office is in a high risk heatwave zone, your scope must now focus on the “Endpoint” rather than the “Office.”
  • Adjust Interface Definitions: Clearly define the boundary between your organisation and your utilities providers if climate change makes power or connectivity a high risk dependency.
  • Document the Decision: Even if you decide climate change does not affect your scope, you must document that you considered it. Silence is not a defence during a Stage 2 audit.
  • Update the Scope Statement: Ensure the final version of your documented information mentions that climate considerations have been factored into the boundary definitions.

How to pass the ISO 27001 Clause 4.3 audit

To successfully pass an audit of ISO 27001 Clause 4.3, a crucial step in achieving ISO 27001 Certification, you must ensure you have implemented the mandatory ISO 27001 documents and ISO 27001 polices. You are going to need to put in place ISO 27001 controls to:

  • Document an ISO 27001 Scope Statement
  • Implement the ISO 27001 standard

What an auditor looks for

The ISO 27001 certification body auditor will ensure:

  • That you have documented your ISO 27001 scope: You must have a documented scope for your Information Security Management System (ISMS). The auditor will check for the existence of a documented scope statement. Utilising the ISO 27001 Scope Template can simplify this process.
  • That you have implemented the scope: You must have implemented the ISO 27001 standard within the defined scope. The auditor will assess whether the requirements of the ISO 27001 standard have been applied effectively to the identified products, services, and areas included within the scope.
  • That the scope was approved: Your documented scope must be formally approved. The auditor will check for evidence of scope approval, such as documented approvals and signatures from relevant management personnel.

When I am conducting a Stage 1 or Stage 2 audit, I am looking for “Scope Integrity.” I want to know if you are telling the truth about where your data is. Here is exactly what I check:

Audit CheckpointThe Lead Auditor’s Question
Documented Information“Show me your scope statement. Is it available to me right now?”
Exclusion Justification“You have excluded your R&D department. Why? Prove to me that no customer data ever touches that department.”
Boundary Proof“You say your scope is ‘London Office only.’ How do you secure the data when your staff work from a train?”
Interface Clarity“Where does your responsibility end and your cloud provider’s begin? Show me the RACI or contract.”

Top 3 mistakes and how to fix them

These are the top 3 mistakes people make for ISO 27001 Scope:

  • Defining an Overly Broad Scope: Including unnecessary areas within the scope of your ISMS can lead to wasted time, resources, and unnecessary costs. Carefully consider and document the specific products, services, and areas that require information security controls.
  • Neglecting Client Expectations: Failing to consider client expectations and requirements within the scope of your ISMS can diminish the value of your certification. Involve clients in the scope definition process to ensure your ISMS addresses their specific needs and concerns.
  • Poor Scope Management: Inadequate documentation, version control, and review of the scope statement can lead to confusion and non-compliance. Maintain accurate and up-to-date records of the scope statement, implement a robust version control system and regularly review and update the scope statement to reflect changes in the organisation or its environment.

How Clause 4.3 Applies to Different Business Models

Business TypeApplicabilityWhy it is ImportantClause 4.3 Scope Examples (Boundaries & Exclusions)
Small BusinessesHigh / EssentialSmall businesses often have limited budgets; a tightly defined scope ensures you aren’t paying to secure non-critical parts of the business.Boundaries: All physical offices and remote staff. Exclusions: Shared building facilities or outsourced payroll processing.
Tech StartupsStrategic / ScalableA clear scope allows startups to scale fast. It demonstrates to investors exactly which assets (usually the core IP and customer data) are protected.Boundaries: SaaS platform infrastructure, DevOps environments, and source code. Exclusions: Third-party marketing agencies or co-working spaces.
AI CompaniesComplex / CriticalDefining the scope is vital to ensure the entire data lifecycle—from ingestion to model training—is covered under the ISMS security controls.Boundaries: Data lakes, GPU compute clusters, and proprietary algorithm repositories. Exclusions: Publicly available datasets used for general pre-training.
Standard / Law / RegulationThe Auditor’s View: Relationship to Clause 4.3 Scoping
NIST CSF 2.0 (Identity: Asset Management & Governance)NIST requires you to identify the assets and systems that support your mission. This is a direct mirror of Clause 4.3. You cannot apply NIST controls until you have defined the “Organizational Context” and the “Scope” of what is being managed.
NIS2 Directive (EU)NIS2 focuses on “Essential” and “Important” entities. Clause 4.3 is the tool you use to map your critical services to these legal categories. If your Clause 4.3 scope excludes a critical service defined under NIS2, you are in breach of EU law.
DORA (Digital Operational Resilience Act)DORA demands a strict definition of the “ICT Risk Management Framework.” For financial entities, Clause 4.3 is the mechanism used to draw the boundary around ICT systems and third-party providers that support critical financial functions.
SOC2 (Trust Services Criteria)SOC2 relies on the “Description of the System.” This is effectively your Clause 4.3 scope statement under a different name. It defines the boundaries of the system, the people, and the data that the auditor will test for security and availability.
EU AI ActThis law requires you to classify AI systems as high-risk or limited-risk. Clause 4.3 is how you document which AI systems are within your management boundary. If you miss an AI tool in your scope, you cannot demonstrate the mandatory transparency and risk oversight required by the Act.
ISO 42001 (Artificial Intelligence Management System)This is the AI-specific twin of ISO 27001. Clause 4.3 in ISO 42001 is identical in intent: you must define the scope of the AI system, including whether you are a provider or a deployer. The two scopes must be synchronized.
UK Data (Use and Access) Act 2025The UK’s evolution of GDPR simplifies administration but doubles down on knowing where your data lives. Clause 4.3 allows you to define a “Reduced Burden Scope” while maintaining high security thresholds for high-risk processing activities.
UK Cyber Security and Resilience BillThis bill expands the UK’s version of NIS2 to include Managed Service Providers (MSPs). Clause 4.3 is vital here: you must define your supply chain boundaries clearly to ensure your “Managed Services” are inside the scope of mandatory reporting.
GDPR / UK GDPR (Article 30 ROPA)The Record of Processing Activities (ROPA) is effectively the “Data Scope” of your business. Clause 4.3 provides the organizational boundary that dictates which data processing activities are included in your privacy management system.
CIRCIA (USA: Cyber Incident Reporting for Critical Infrastructure Act)CIRCIA requires 72-hour reporting for “Covered Entities.” Clause 4.3 is the exercise of determining if your organization, or a specific business unit, falls into one of the 16 critical infrastructure sectors mandated by the US government.
EU Product Liability Directive (PLD) UpdateThe updated PLD treats software as a product. Clause 4.3 is used to define the “Development Scope.” If you develop software, your ISMS scope must include the SDLC (Software Development Life Cycle) to mitigate strict liability for cybersecurity flaws.
ECCF (European Cybersecurity Certification Framework)ECCF introduces harmonized security labels. Clause 4.3 is the process of defining the “Target of Evaluation” (TOE). You must match your ISMS scope to the specific product or service you are seeking an EU-wide security label for.
HIPAA (Security Rule 45 CFR § 164.306)HIPAA requires Covered Entities to protect Electronic Protected Health Information (ePHI). Clause 4.3 is the boundary-setting exercise that identifies every system and person that creates, receives, maintains, or transmits ePHI.
California Data Laws (CCPA / CPRA)CCPA/CPRA focus on the “Business” and “Service Provider” relationship. Clause 4.3 maps these relationships. It defines whether a specific business unit or legal entity is the “Controller” or “Processor” of Californian resident data.

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top