ISMS Scope Statement
Describe your organization's ISMS scope and 'context of the organization' to meet the requirements of ISO 27001:2022 Clause 4
Written By Micah
This document can be used to describe the scope and context of the Information Security Management System or ISMS (and Privacy Information Management System or ISMS+PIMS). This document is derived from ISO 27001:2022, Clauses 4.1 and 4.3, and ISO 27701:2019, Clause 5.2.1 PII Processor, as well as contractual, legal, and regulatory requirements. This document will be shared with Internal Audit and the ISO Assessor or Certifier.
Commonly associated evidence:
Scope of ISMS (+PIMS)
Who needs a policy like this?
Organizations that adhere to ISO 27001 and ISO 27701
How to use the template:
Click on the link above to access the template
If you are a Google Workplace organization, make a copy by going to File > Make a copy
If you are not a Google Workplace organization, download a copy by going to File > Download and selecting your preferred file type (available as DOCX, PDF, and more)
Review and then remove instructional text
Save in a centralized place
Attach to evidence either through Integrations, Automated Collection, or direct upload
If you need help using the template, please let us know.