“The organization shall determine the boundaries and applicability of the information security management system to establish its scope.”ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · 2022 · ISO/IEC 27001:2022, clauza 4.3 «Determining the scope of the information security management system»
A scope too narrow passes the audit but convinces no customer, and one too broad never gets finished.
Clause 4 asks for three things before any control. First, the internal and external issues relevant to the organisation's purpose and to the intended outcomes of the system. Then the interested parties and their requirements — customers, regulators, employees, suppliers — because a contractual requirement nobody identified becomes a nonconformity at the first audit. Only then comes the scope, at 4.3: the boundaries and applicability of the system, taking into account the issues from 4.1, the requirements from 4.2, and the interfaces with activities performed by other organisations. The classic mistake sits at 4.3, in both directions. A scope that is too narrow, one team or one product, passes the audit easily but convinces no customer who asks what exactly is certified. A scope that is too broad, declared before the processes exist, turns certification into a project that never ends. Amendment 1:2024, published in February 2024, added to 4.1 and 4.2 the duty to consider climate change as a possibly relevant issue.
Why it matters A scope cut only to pass the audit produces a certificate the sales team cannot use.