ISMS Scope Statement

Describe your organization's ISMS scope and 'context of the organization' to meet the requirements of ISO 27001:2022 Clause 4

Written By Micah

This document can be used to describe the scope and context of the Information Security Management System or ISMS (and Privacy Information Management System or ISMS+PIMS). This document is derived from ISO 27001:2022, Clauses 4.1 and 4.3, and ISO 27701:2019, Clause 5.2.1 PII Processor, as well as contractual, legal, and regulatory requirements. This document will be shared with Internal Audit and the ISO Assessor or Certifier.

Commonly associated evidence:

  • Scope of ISMS (+PIMS)

Who needs a policy like this?

  • Organizations that adhere to ISO 27001 and ISO 27701

How to use the template:

  • Click on the link above to access the template

    • If you are a Google Workplace organization, make a copy by going to File > Make a copy

    • If you are not a Google Workplace organization, download a copy by going to File > Download and selecting your preferred file type (available as DOCX, PDF, and more)

  • Review and then remove instructional text

  • Save in a centralized place

  • Attach to evidence either through Integrations, Automated Collection, or direct upload

If you need help using the template, please let us know.