Scope of the ISMS Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Scope of the ISMS flashcards as text
A multinational company defines its ISMS scope to cover only its US operations. Which obligation must it still consider?
Answer: Interfaces with out-of-scope regions that could affect information security
Even with a limited scope, the organization must consider interfaces and dependencies with out-of-scope areas that could affect the ISMS's effectiveness.
In ISO 27001, what is the relationship between ISMS scope and the Statement of Applicability (SoA)?
Answer: The SoA lists which Annex A controls apply based on the defined scope
The Statement of Applicability documents which controls from ISO 27001 Annex A are applicable within the defined ISMS scope and justifies any exclusions.
A hospital defines its ISMS scope to include patient data systems. Which regulation is MOST likely an external issue shaping this scope?
Answer: HIPAA privacy and security rules
HIPAA (Health Insurance Portability and Accountability Act) directly governs the protection of patient health information, making it a key external driver for the hospital's ISMS scope.
What does 'physical location' mean in the context of ISMS scope definition?
Answer: The geographic sites and facilities included within the ISMS boundary
Physical location in ISMS scope refers to which geographic sites and facilities are included within the boundary of the information security management system.
An organization's ISMS scope excludes cloud services used to process customer data. What is the PRIMARY concern with this approach?
Answer: Customer data may be processed outside any ISMS controls
Excluding cloud services that process customer data means significant information assets are outside the ISMS controls, exposing the organization to unmanaged security risks.
Which term describes the set of assets, processes, systems, and locations managed under the ISMS?
Answer: ISMS scope
ISMS scope defines the assets, processes, systems, people, and physical locations that fall under the information security management system.
Why might an organization choose a narrow ISMS scope for initial certification?
Answer: To reduce implementation complexity and achieve certification faster on a manageable area
Starting with a narrow scope allows organizations to demonstrate ISMS competence in one area, then expand the scope progressively in future certification cycles.