Skip to main content
Kayra Patent · Management systems

ISO/IEC 27001 Scope: Cloud Services, Remote Work and Customer Data

Information security scope is more than a server inventory. Defining services, staff, customer information and external providers together clarifies applications and everyday security decisions.

Questions for your situation

If every system is in the cloud, do we still need our own information security arrangements?

The provider's certificate does not automatically cover your user permissions, sharing decisions or incident response. Distinguish responsibilities through contracts and architecture. Include administrator access, restoration of backups, log availability and exit planning in your own risk assessment. Cloud hosting does not remove the controls managed by the customer organisation.

Can we include only one software product and exclude the rest of the company?

A limited scope may be possible, but supporting HR, device management, support, development and supplier processes cannot be ignored. Explain dependencies on shared or external activities. The certificate wording must not imply assessment of the whole company or every product. Map the service before determining its boundaries.

How do home working and personal devices affect scope?

Access to information and control arrangements matter more than location alone. Identify accessible data, device protection, permission removal and incident reporting. Establish risk-based acceptance conditions rather than assuming personal devices must always be prohibited or unrestricted. Rehearse arrangements for employee departure or device loss before they are needed.

Must every security control be implemented?

Justify control selection through risk assessment and applicable obligations. The Statement of Applicability should consistently describe necessary controls, inclusion reasons and implementation status, with explanations for excluded reference controls. Use actual data and service flows rather than ticking a prepared list. Include specific controls required by customer contracts.

Does a data breach mean the certificate is invalid?

Certification does not guarantee that no incident will occur. Assessment considers detection, containment, reporting evaluation and remediation. Plan evidence preservation alongside service recovery. Failure to operate controls or meet certification conditions requires separate consideration. Incident records are important evidence when the certification body's review addresses certificate status.

Is the existing scope sufficient when a customer requests data transfers to another country?

Identify data types, recipients, hosting locations and subprocessors. Evaluate security risks separately from data protection and contractual requirements. System certification does not replace a lawful transfer mechanism. Update risk assessment and scope information where architecture, permissions or provider conditions change, and allow time for those reviews.

Official sources

Content reviewed:

QUICK QUOTE FORM

Get a scope-based assessment

Share the subject, organisation or product, target market, current evidence and target date. The team can then separate consultancy, official fees, independent evaluation and realistic timing.

QUICK QUOTE FORM

Get a scope-based assessment

A telephone number is required. You may leave the email field blank.

Your information is used only to respond to this enquiry. Privacy notice