ISO/IEC 27001 Scope: Cloud Services, Remote Work and Customer Data
Information security scope is more than a server inventory. Defining services, staff, customer information and external providers together clarifies applications and everyday security decisions.
Questions for your situation
If every system is in the cloud, do we still need our own information security arrangements?
The provider's certificate does not automatically cover your user permissions, sharing decisions or incident response. Distinguish responsibilities through contracts and architecture. Include administrator access, restoration of backups, log availability and exit planning in your own risk assessment. Cloud hosting does not remove the controls managed by the customer organisation.
Can we include only one software product and exclude the rest of the company?
A limited scope may be possible, but supporting HR, device management, support, development and supplier processes cannot be ignored. Explain dependencies on shared or external activities. The certificate wording must not imply assessment of the whole company or every product. Map the service before determining its boundaries.
How do home working and personal devices affect scope?
Access to information and control arrangements matter more than location alone. Identify accessible data, device protection, permission removal and incident reporting. Establish risk-based acceptance conditions rather than assuming personal devices must always be prohibited or unrestricted. Rehearse arrangements for employee departure or device loss before they are needed.
Must every security control be implemented?
Justify control selection through risk assessment and applicable obligations. The Statement of Applicability should consistently describe necessary controls, inclusion reasons and implementation status, with explanations for excluded reference controls. Use actual data and service flows rather than ticking a prepared list. Include specific controls required by customer contracts.
Does a data breach mean the certificate is invalid?
Certification does not guarantee that no incident will occur. Assessment considers detection, containment, reporting evaluation and remediation. Plan evidence preservation alongside service recovery. Failure to operate controls or meet certification conditions requires separate consideration. Incident records are important evidence when the certification body's review addresses certificate status.
Is the existing scope sufficient when a customer requests data transfers to another country?
Identify data types, recipients, hosting locations and subprocessors. Evaluate security risks separately from data protection and contractual requirements. System certification does not replace a lawful transfer mechanism. Update risk assessment and scope information where architecture, permissions or provider conditions change, and allow time for those reviews.
Share the subject, organisation or product, target market, current evidence and target date. The team can then separate consultancy, official fees, independent evaluation and realistic timing.