Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

Is it possible to restrict the scope of the ISMS to just one department or business unit, at least initially?

0
Posted

Is it possible to restrict the scope of the ISMS to just one department or business unit, at least initially?

0

Restricting the scope of the ISMS may reduce some of the effort and costs involved in the implementation but also reduces the realisable benefits, hence the net business value of the ISMS may well be lower. It is not necessarily such an easy option as it might at first appear, as your supplementary question implies. The scope boundary can be a problem since, by definition, everything outside the scope is inherently less trustworthy than that within. Information security risks within scope of the ISMS (i.e. risks directly affecting the in-scope area) are assessed and treated, and this includes risks affecting the information flows going into or out of the scoped area.

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123