Training Module
ISMS Scope & Statement of Applicability
Define clear ISO/IEC 27001 ISMS scope and boundaries and maintain a defensible Statement of Applicability (SoA)
Overview
ISMS scope and Statement of Applicability decisions often look tidy on paper while the real organisation remains messier: shared platforms, regional teams, suppliers, cloud services, outsourced processes, customer responsibilities and changing service models do not fit neatly into a certificate sentence.
This module uses the evolving Northstar case to practise defining a defensible ISMS scope, making boundary and interface decisions visible, and building SoA rationale that can support risk work, customer assurance and management review. The focus is practical management-system judgement, not a generic ISO/IEC 27001 overview or a control-by-control Annex A walkthrough.
Applicable environments
This module applies to organisations implementing or operating an information security management system (ISMS) in line with ISO/IEC 27001. It focuses on how the standard’s requirements are interpreted and applied in practice within real organisational contexts.
The content is relevant for organisations seeking certification as well as for those using ISO/IEC 27001 as a reference framework to structure responsibilities, processes, and controls in the information security domain.
Target audience
People involved in designing, building, operating, or improving an ISMS aligned with ISO/IEC 27001
Executives and department heads accountable for the effectiveness and performance of an ISMS
Those responsible for processes, policies, assets, risks, and controls related to information security
Auditors of ISO/IEC 27001 who want to deepen their understanding of management-side best practices (not audit technique)
Decision support
Is this module for you?
Agenda
ISMS scope as decision frame
Services, processes and information assets
Boundaries, interfaces and retained responsibility
Applicability rationale and exclusions
SoA structure, status and traceability
Maintenance, assurance and management review
Show detailed agenda...
Learning outcomes
Key outcomes
Define an ISO/IEC 27001 ISMS scope that explains services, boundaries, exclusions, interfaces and assumptions
Clarify retained responsibility across shared platforms, suppliers, outsourced processes and customer interfaces
Build SoA applicability rationale that links scope, risk inputs, control status, evidence and review triggers
Additional capabilities
Connect ISMS scope to services, processes, information assets, obligations and assurance needs
Distinguish applicability, exclusion rationale, implementation status and operational evidence
Use supplier, platform, service and AI workflow changes as scope and SoA review triggers
Prepare customer-safe scope and SoA assurance wording for management review
Use AI support to compare artefacts and challenge weak rationale without replacing accountability
Materials
Learning materials
Slide deck
Participant workbook
Templates & tools
Practical, reusable artefacts to apply the module directly to your organisation.
ISMS scope statement template
Service, process and information asset coverage worksheet
Scope interface and retained responsibility map
Applicability rationale and exclusion checklist
Statement of Applicability working template
Scope and SoA review trigger worksheet
AI prompt set and safeguards checklist for scope and SoA review
Confirmation
Certificate of completion
Overview
Dates
Bespoke
Module ID
HAM-IS-S-01
Discipline
ISO standard
Standard clause
4: Context of the organisation
Domains
Target audience
Delivery
Live virtual delivery
This module is delivered live online and combines conceptual framing, discussion, case work and direct interaction with the instructor.
Custom delivery options
For organisations with specific constraints or learning objectives, the module can be adapted in format or scope, including in-house delivery and contextualised case material.
Upcoming course runs
A public cohort is currently not scheduled. If you register your interest, we will notify you when a new public cohort is scheduled or suitable delivery options become available.
For an optimal learning experience
Prerequisites & preparation
This module is designed as part of a modular training approach. Topics are deliberately distributed across modules and are not repeated in full, in order to avoid unnecessary redundancy. Each module is self-contained and can be taken on its own. Where prior knowledge or experience is helpful, this is indicated below so you can decide whether any preparation is useful for you.
Assumed background
No formal prerequisites. The module is designed as a stand-alone entry point for defining ISMS scope and maintaining a defensible SoA.
Helpful background includes:
General familiarity with information security, ISO/IEC 27001 or management-system work
Practical exposure to services, processes, suppliers or information assets
Comfort reasoning about context, interested parties, interfaces and outsourced processes
Experience with customer assurance or evidence questions is useful, but not required
Preparatory modules
Supporting modules (optional)
Helpful if you want to deepen related skills, but not required to participate effectively.


