1.3 Determining ISMS Scope & Boundaries (Clause 4.3)

Key Takeaways

  • Clause 4.3 mandates that organizations explicitly determine and document the boundaries and applicability of the ISMS to establish its official scope.
  • ISMS scope definition must incorporate the internal and external issues (Clause 4.1), interested party requirements (Clause 4.2), and interfaces/dependencies with third parties.
  • Scope boundaries must be clearly articulated across physical, organizational, and technological dimensions.
  • While an organization may limit its ISMS to specific business units, products, or physical locations, no mandatory requirements of Clauses 4 through 10 can be excluded from the defined scope.
  • All interfaces and dependencies with external entities, third-party service providers, and shared infrastructure outside the scope boundary must be explicitly identified and managed.
Last updated: July 2026

1.3 Determining ISMS Scope & Boundaries (Clause 4.3)

Once an organization understands its context (Clause 4.1) and interested party requirements (Clause 4.2), it must establish the exact boundaries within which the Information Security Management System (ISMS) will operate. ISO/IEC 27001 Clause 4.3 requires the organization to determine the boundaries and applicability of the ISMS to establish its scope.

Defining the scope is one of the most critical responsibilities of a Lead Implementer. A scope that is too narrow may fail to protect critical organizational assets and disappoint key stakeholders. Conversely, an overly broad scope can overwhelm organizational resources and lead to project failure.


Mandatory Inputs for Scope Determination

ISO/IEC 27001 Clause 4.3 explicitly mandates that when determining the ISMS scope, the organization shall consider:

  1. The external and internal issues referred to in Clause 4.1 (PESTLE and SWOT context findings).
  2. The requirements of interested parties referred to in Clause 4.2 (statutory, regulatory, and contractual obligations).
  3. The interfaces and dependencies between activities performed by the organization and those performed by external parties or other internal divisions.
       [ Clause 4.1 Context ] -----\
                                    \
       [ Clause 4.2 Requirements ] ---> [ CLAUSE 4.3 ISMS SCOPE STATEMENT ]
                                    /   (Mandatory Documented Information)
       [ External Interfaces ] ----/

Defining Scope Boundaries: The Three Dimensions

To ensure completeness, a Lead Implementer must analyze and define the ISMS boundary across three primary dimensions:

1. Organizational Boundaries

The organizational boundary defines which legal entities, divisions, business units, operational teams, or functions fall inside the ISMS.

  • Full Enterprise Scope: Encompasses the entire organization across all business units and subsidiaries.
  • Targeted / Segmented Scope: Restricted to specific business units (e.g., Payment Processing Division, Software R&D Division, Cloud Operations Team) or specific services offered to clients (e.g., Managed Security Services Platform).

2. Physical Boundaries

The physical boundary specifies the physical geographic locations, facilities, real estate, and physical access security zones where in-scope activities take place.

  • Physical Sites: Headquarters buildings, regional offices, data center facilities, co-location cages, warehousing facilities, and customer support centers.
  • Remote & Distributed Work Environments: Clearly defining how home offices, mobile workers, and remote work environments are accounted for within physical control boundaries.

3. Technological & Information Systems Boundaries

The technological boundary defines the IT infrastructure, software applications, networks, databases, communication channels, and information assets included in the ISMS.

  • Infrastructure & Hardware: On-premises server racks, cloud tenant environments (AWS, Azure, GCP), network routers, firewalls, user endpoints (laptops, mobile devices).
  • Data & Applications: Specific databases containing sensitive data (e.g., PII, PHI, financial records), proprietary source code repositories, ERP systems, and API endpoints.

Scope Boundaries Framework Matrix

Boundary DimensionDefinition ParametersInclusion CriteriaCommon Pitfalls & Audit Warnings
OrganizationalBusiness units, legal entities, operational teams, corporate functions.All teams directly involved in delivering the in-scope service or processing target data.Excluding core support functions (e.g., HR screening, Legal, IT helpdesk) that service in-scope personnel.
PhysicalHeadquarters, data centers, branch offices, co-location cages, remote sites.Facilities harboring in-scope servers, network infrastructure, or personnel.Omitting third-party cloud data centers or ignoring physical security controls for remote worker locations.
TechnologicalCloud infrastructure, networks, databases, applications, endpoints.All systems that process, store, or transmit in-scope information assets.Leaving out shared corporate services (e.g., Active Directory/IDP, centralized logging) that interface with in-scope systems.
Interfaces & ExternalCloud SaaS/PaaS/IaaS vendors, outsourced vendors, managed service providers.Boundaries where data crosses from in-scope infrastructure to external third-party control.Failing to establish formal operational boundaries and vendor security monitoring at third-party connection points.

Rules Governing Scope Exclusions

A common area of confusion during certification audits involves scope exclusions. Lead Implementers must strictly adhere to ISO/IEC 27001 rules regarding exclusions:

1. Mandatory Clauses (Clauses 4 through 10) Cannot Be Excluded

In ISO/IEC 27001:2022, no requirement from Clauses 4 to 10 can be excluded, regardless of organizational size, industry, or operational nature. All 7 normative management clauses must be fully implemented within the defined scope boundary.

2. Organizational / Physical Scope Tailoring Is Permitted

An organization is legally allowed to define a limited organizational or physical scope (e.g., certifying only the Frankfurt Data Center operations and excluding North American retail stores). However, the scope statement must accurately describe this boundary so that clients and auditors are not misled regarding what is certified.

3. Annex A Control Exclusions

Controls listed in Annex A can only be excluded if they are deemed non-applicable following a formal risk assessment and statement of justification in the Statement of Applicability (SoA) (Clause 6.1.3). For example, if an organization operates 100% in the cloud and owns zero physical servers or data center real estate, physical cabling controls (Annex A.7.12) may be excluded with clear justification.


Managing Interfaces, Dependencies, and Outsourced Processes

Information systems rarely operate in isolation. In modern cloud ecosystems, the ISMS boundary interfaces constantly with third-party service providers (IaaS, PaaS, SaaS) and shared internal services.

Shared Responsibility Model

When in-scope systems rely on cloud service providers (e.g., AWS, Microsoft Azure), the Lead Implementer must clearly document the demarcation line of responsibility:

  • Cloud Provider Scope: Physical data center security, hypervisor isolation, underlying hardware maintenance.
  • Organization ISMS Scope: Operating system patching, customer database encryption, identity and access management (IAM), firewall configuration, application security.

The Lead Implementer must ensure that third-party dependencies are controlled through contractual agreements, vendor risk assessments, and monitoring mechanisms (Annex A.5.19–A.5.22).


Documented Information Requirements: The Scope Statement

Clause 4.3 explicitly mandates that the ISMS scope shall be available as documented information. Third-party certification auditors will inspect the written Scope Statement as one of the first audit artifacts.

Key Elements of a Compliant Scope Statement

A robust, auditor-approved ISMS Scope Statement must include:

  1. Official Title and Executive Summary: Clear identification of the organization and purpose.
  2. Business Activities and Services Covered: Precise description of products, services, or operational processes certified (e.g., "The Information Security Management System covers the design, development, deployment, operation, and customer support of the SaaS Payment Platform...").
  3. Organizational and Physical Boundaries: Exact legal entities, divisions, and physical addresses included.
  4. Technological Boundaries: Named cloud environments, production networks, and system boundaries.
  5. Key Exclusions & Interface Demarcation: Explicit statement of boundary limits and external interfaces.

Practical Implementation Scenario

Scenario: Global Enterprise Corp operates three business units: Retail Operations, Logistics, and Cloud SaaS Solutions. Management decides to certify only the Cloud SaaS Solutions unit under ISO/IEC 27001 to satisfy European client demands. During the scope scoping phase, the Lead Implementer notices that the Cloud SaaS unit relies on Global Enterprise Corp's centralized HR team for employee onboarding/screening and centralized IT for corporate Active Directory authentication.

Lead Implementer Guidance: The Lead Implementer cannot simply exclude HR screening or Active Directory authentication from the ISMS because doing so creates unmanaged security dependencies. The Lead Implementer defines the primary ISMS scope as the Cloud SaaS Solutions business unit, but explicitly includes the specific interfaces and operational dependencies on centralized HR (for Annex A.6 personnel controls) and centralized IT Active Directory (for Annex A.5.15 access management) within the ISMS boundary scope documentation. This ensures all critical security inputs feeding the SaaS environment are audited and managed under the ISMS.

Loading diagram...
ISMS Boundary Scoping & Interface Demarcation Diagram
Test Your Knowledge

An organization is defining its ISMS scope under ISO/IEC 27001 Clause 4.3. The Chief Security Officer asks whether the organization can exclude Clause 9.2 (Internal Audit) from the ISMS scope because an external auditing firm performs annual reviews.

A
B
C
D
Test Your Knowledge

Which three mandatory inputs must an organization evaluate when determining the scope of its Information Security Management System in accordance with Clause 4.3?

A
B
C
D
Test Your Knowledge

A cloud-native technology company operates entirely within a third-party Infrastructure-as-a-Service (IaaS) environment. How should the Lead Implementer address physical data center security controls when defining the ISMS scope and Statement of Applicability?

A
B
C
D