Training module

ISMS Scope & Statement of Applicability

Define clear ISO/IEC 27001 ISMS scope and boundaries and maintain a defensible Statement of Applicability (SoA)

Information SecurityManagement System Manager
Networked security icons with scope boundaries and control links, representing ISMS scope definition, system boundaries and the Statement of Applicability under ISO/IEC 27001.

Define the frame that makes ISMS decisions defensible

Build practical judgement for ISO/IEC 27001 scope and Statement of Applicability work: services, boundaries, interfaces, outsourced processes, shared responsibilities, control applicability, evidence reality and review triggers.

Overview

What this module is about

ISMS scope and Statement of Applicability decisions often look tidy on paper while the real organisation remains messier: shared platforms, regional teams, suppliers, cloud services, outsourced processes, customer responsibilities and changing service models do not fit neatly into a certificate sentence.

This module uses the evolving Northstar case to practise defining a defensible ISMS scope, making boundary and interface decisions visible, and building SoA rationale that can support risk work, customer assurance and management review. The focus is practical management-system judgement, not a generic ISO/IEC 27001 overview or a control-by-control Annex A walkthrough.

Audience

Who it is for

Management system implementers and coordinators

Executives and department heads accountable for management system performance

Those responsible for processes, policies, assets, risks and controls

Auditors seeking insight into management-side practice, not audit technique

Consultants working on management system design, governance or improvement

Decision supportIs this module for you?

It is a good fit if you…

work with ISMS implementation, scope definition, SoA maintenance or customer assurance.

need to connect ISO/IEC 27001 scope to real services, processes, information assets and obligations.

see unclear boundaries across shared platforms, suppliers, outsourced processes or regional teams.

want control applicability and exclusion rationale that can survive review, audit and management questions.

are preparing to strengthen an ISMS before certification, recertification, customer assurance or major change.

It may not be the best fit if you…

want only a short overview of ISO/IEC 27001 clauses.

are mainly looking for technical hardening, tool configuration or penetration testing.

want a full information security risk assessment or residual-risk acceptance course.

expect a control-by-control Annex A interpretation workshop.

already have a clearly owned, maintained and evidence-backed ISMS scope and SoA that works in practice.

Agenda

What is taught

6 parts
01ISMS scope as decision frame

Read scope wording before trusting it

Use context, interested parties and obligations at the level needed for ISMS decisions

Define what scope must support for risk, controls, assurance and management review

02Services, processes and information assets

Start from customer-facing services and management-system outcomes

Connect services and processes to primary and supporting information assets

Repair scope wording so coverage, exclusions and assumptions are clear

03Boundaries, interfaces and retained responsibility

Map organisational, technical, supplier and customer boundaries

Clarify outsourced processes, supplier-operated controls and shared platforms

Assign internal ownership for interfaces, evidence and escalation

04Applicability rationale and exclusions

Decide whether selected controls are applicable, not applicable or partly applicable

Test exclusion rationale against scope, obligations, risk inputs and retained responsibility

Use AI-assisted review to challenge weak rationale without outsourcing judgement

05SoA structure, status and traceability

Separate applicability, rationale, implementation status, references and ownership

Find gaps between documented status and evidence reality

Identify handoffs to risk management, supplier management and operational control

06Maintenance, assurance and management review

Use service, supplier, platform, incident and AI workflow changes as review triggers

Prepare customer-safe assurance wording without overclaiming coverage

Turn scope and SoA status into concise management-review input

Outcomes

Learning outcomes

01

Define an ISO/IEC 27001 ISMS scope that explains services, boundaries, exclusions, interfaces and assumptions

02

Clarify retained responsibility across shared platforms, suppliers, outsourced processes and customer interfaces

03

Build SoA applicability rationale that links scope, risk inputs, control status, evidence and review triggers

Connect ISMS scope to services, processes, information assets, obligations and assurance needs

Distinguish applicability, exclusion rationale, implementation status and operational evidence

Use supplier, platform, service and AI workflow changes as scope and SoA review triggers

Prepare customer-safe scope and SoA assurance wording for management review

Use AI support to compare artefacts and challenge weak rationale without replacing accountability

Materials

The content and the assessment

Written module

The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.

Exercises

Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.

On completion

The assessed exercises must be passed before the certificate is issued.

Scheduling

No public run of ISMS Scope & Statement of Applicability is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.

Module facts

Module ID
HAM-IS-S-01
Download fact sheet (PDF, 4.7 MB) →

Case organisation

You work inside a company that already has the problem

Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.

Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.

Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes

Not a case study
Nothing is summarised for you; the evidence is where it would really be

It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after

It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions

Why it matters

Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.

How we teach →

Delivery & dates

How this module reaches you

Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.

No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.

Want this module scheduled?

We will tell you when the next run is scheduled, or run this module in-house with your own case material.

Not sure it is the right module?

Describe your context in a short message and we will tell you honestly.

No obligation

Tell us what would work and we will come back with dates, or with an in-house proposal if you would rather run this for a group on your own management system.
About ISMS Scope & Statement of Applicability · HAM-IS-S-01

No account needed. We reply personally, usually within a working day. Sending is not switched on yet, so write to us in the meantime: contact us.

Decision support

Describe your role and your context in a short message and we will tell you honestly whether this module is the right one, or point you at a better fit.
About ISMS Scope & Statement of Applicability · HAM-IS-S-01

No account needed. We reply personally, usually within a working day. What happens to your message is set out in the privacy policy.