Define scope & context
Set the boundary of your ISMS and understand the organisation and interested parties. Scope is the single biggest lever on cost and effort, so getting it tight and documented pays off everywhere downstream.
Key activities
- Understand internal & external issues (Clause 4)
- Identify interested parties & their requirements
- Define the ISMS scope & boundary
- Draft the information security policy
Deliverable






















