Define ISMS scope + boundary for SwiftLend NBFC
Scenario
SwiftLend (₹500 cr AUM NBFC, RBI-regulated) has decided to pursue ISO 27001 certification. They have: Corporate HQ (Mumbai, 200 staff), a Bangalore engineering office (60 devs), a call centre (Chennai, 150 seats, mostly contractors), a cloud infrastructure (AWS Mumbai + Singapore), 3 SaaS vendors handling customer data, and a mobile app (customer-facing, ~1M installs). Board-appointed timeline: 12 months to certification. Before you can start ANYTHING else, you must define the ISMS Scope Statement — the single most-consequential document in an ISO 27001 programme.
Your role
You are the ISMS Manager.
Your task
Draft the ISMS Scope Statement (Clause 4.3 of ISO 27001:2022). Must state: 1. What is INCLUDED (locations, services, business units, technologies) 2. What is EXCLUDED and WHY (with justification) 3. Interfaces + dependencies with excluded areas 4. Applicable regulatory context Then add a 2-sentence 'why this scope' justification the CEO can defend to the board.
Deliverable format: Formal Scope Statement document, ~400-700 words
Toolkit
- ISO 27001:2022 Clause 4.3 — Determining the scope of the ISMS
- Common excluded scopes: physical office security (kept under separate facility policy), personal devices, third-party payment processor (their PCI scope, not yours)
- Interfaces MUST be documented even for excluded areas
- Common trap: scoping so narrow that customer-facing services are excluded = worthless cert
Success criteria (what the AI grades against)
- Included scope covers the customer-facing services + all data-handling operations
- Chennai call centre correctly assessed (contractor risk — probably in scope)
- Regulatory context includes RBI + DPDPA (missing DPDPA = fail)
- Excluded items have WRITTEN JUSTIFICATION not just 'excluded'
- Interfaces to excluded scope are documented (e.g. 'call centre uses same identity provider — access control interface exists')
Log in to submit your deliverable for AI review.
Log in / Register