All data is fictional

ISMS Scope

ISO 27001:2022 Clause 4.3  ·  Version 3.1  ·  Approved 8 Jan 2026

Owner: Jane Cooper (CISO)

Document Completion

12 of 13 sections completed

92%
1. Purpose & Objectives
ISO 27001:2022 Clause 4.3  ·  Complete
People24
Locations3

The purpose of AcmeCorp's Information Security Management System (ISMS) is to protect the confidentiality, integrity, and availability of all information assets critical to the organisation's operations and its customers' data.

The ISMS objectives are to systematically manage information security risks, comply with applicable legal and contractual obligations, and continually improve security posture through a cycle of plan, do, check, and act.

2. Organisational Context
ISO 27001:2022 Clause 4.1  ·  Complete
Departments8
Interested Parties12

AcmeCorp is a SaaS technology company providing cloud-based business management solutions to mid-enterprise clients across the UK and EU. The company operates in a regulated environment subject to GDPR, ISO 27001, NIS 2, and contractual SOC 2 Type II requirements from enterprise customers.

Key external factors include evolving data protection legislation, growing cyber threat landscapes, and client contractual requirements for independent assurance of information security controls.

3. Scope Statement
ISO 27001:2022 Clause 4.3  ·  Complete
4. Organisational Boundaries
ISO 27001:2022 Clause 4.3  ·  Complete
In ScopeAll departments
Contractors18 in scope

All full-time employees, part-time employees, contractors, and authorised third parties accessing AcmeCorp systems fall within scope. The boundaries include all business units: Engineering, Product, InfoSec, Operations, Sales, Finance, HR, and Legal.

5. Physical Scope
ISO 27001:2022 Clause 7.1  ·  Complete
Sites3
Data Centres2 (AWS)
London HQ
120 Moorgate, EC2M 6XH
200 staff · Primary ISMS site
Manchester Office
1 Spinningfields, M3 3AP
45 staff · Engineering hub
Dublin Office
Silicon Docks, D02 X285
30 staff · EU operations
6. Information Assets
ISO 27001:2022 Clause 8.1  ·  Complete
Critical14

All information assets are registered in the Asset Register. Asset classification follows the Data Classification Policy with four tiers: Public, Internal, Confidential, and Restricted. Critical assets include customer data, authentication systems, source code repositories, and financial records.

7. Technology Scope
ISO 27001:2022 Clause A.8  ·  Complete

In-scope technology includes: production SaaS platform (AWS eu-west-1, eu-central-1), CI/CD pipeline, corporate IT estate, endpoint devices, communications infrastructure, and authorised third-party integrations.

AWS Cloud (eu-west-1)
AWS Cloud (eu-central-1)
GitHub Enterprise
Okta SSO
Datadog Monitoring
Microsoft 365
Salesforce CRM
Corporate VPN
8. Risk Management Framework
ISO 27001:2022 Clause 6.1 & 8.2  ·  Complete
Active Risks61
Critical5

Risks are assessed using a 5×5 likelihood vs impact matrix. All risks scoring 15 or above require CISO approval for acceptance. The Risk Register is reviewed quarterly and after significant organisational or environmental changes.

9. Control Framework
ISO 27001:2022 Annex A  ·  Complete
Controls93
Implemented68 (73%)

The control set is based on ISO 27001:2022 Annex A (93 controls across 4 domains). The Statement of Applicability documents all applicable controls, justifications for inclusion/exclusion, and implementation status. Additional controls from SOC 2, GDPR, and BSI C5 are tracked as supplementary mappings.

10. Compliance & Governance
ISO 27001:2022 Clause 9  ·  Complete

The ISMS is governed by the Information Security Steering Committee, chaired by the CISO. The committee meets quarterly. Internal audits are conducted annually and the management review cycle follows the annual operations calendar.

11. ISMS Records
ISO 27001:2022 Clause 7.5  ·  Complete
Evidence Items87

All documented information required by ISO 27001 is maintained in Salvinta GRC. Records include policy documents, risk assessments, audit reports, management review minutes, and training records with defined retention periods per the Records Retention Schedule.

12. Interfaces & Dependencies
ISO 27001:2022 Clause 4.2  ·  Complete

The ISMS interfaces with the following external parties: cloud infrastructure provider (AWS), identity provider (Okta), software development tooling (GitHub), and key subprocessors identified in the DPA register. Each carries contractual security obligations reviewed annually.

13. Exclusions & Justifications
ISO 27001:2022 Clause 4.3 Note  ·  In Review

The following areas are currently excluded from ISMS scope with documented justifications:

Excluded AreaJustificationReview Date
Legacy CRM (Sunset Q2 2026)EoL system being decommissioned; data migrated to Salesforce30 Jun 2026
US-based subsidiary (incorporation pending)Legal entity not yet operational; to be incorporated Q3 202601 Sep 2026