Determining the Scope Statement

When determining the scope, consider what your customers are concerned about and capture the processes that are used to define your scope. The ISO certificate can be a marketing tool and a market differentiator for your organization.
The ISO 27001 scope statement is one of the first steps for building your ISMS. Although it is just a short separate document or small paragraph in your security policy, it is one of the most important aspects of the certification. The scope statement is defined in the ISO/IEC 27001:2013 under section 4. It shortly describes the purpose or context of your organization and what processes are relevant to run your business. In other words, it defines the boundaries, subject, and objectives of your ISMS.
Some examples of scope statements include:
Long example –
Design, Development, Manufacturing, Operations, Sales, Customer Experience,
Services and Support for Networking, Data Center, Communications, Video, Collaboration, and Security Products, Solutions, and Services related to the Wizbang Solution.
Specific processes around a solution –
Development, provisioning, and customer support of software for designing, automating, and analyzing business processes (for on-premise and cloud product offerings).
Associated physical security –
The physical and logical protection of customer and company data and associated information assets in use, stored, and accessed in the company office or remotely for the provision of professional services that include service management, cyber security operations, and associated consulting services.
Key aspects to consider when developing the scope are:
- business processes that are important to operate your organization
- mandatory laws and regulations
- all interested and relevant parties (internal and external) for your ISMS or information security
- norms and dependencies
When determining the scope, consider what your customers are concerned about and capture the processes that are used to define your scope. The ISO certificate can be a marketing tool and a market differentiator for your organization.
Think about the business model of your organization and what processes are critical to the business. What business locations should be included, what type of information is stored, and what services and processes do the organization offer? Identify relevant and important stakeholders and key players (external and internal) and gather feedback for expectations about information security, IT security, or other areas that need to be protected.
The scope statement doesn’t need to be long or detailed, it simply needs to convey the processes that are going to be included in the certification. Just remember this statement will be displayed on the certificate and should accurately reflect the areas of certification.

Ready to define your scope statement?
Get a proposal in 48 hours. Start your compliance journey today.
Related articles
_converted.avif)
How Your Customer Success Manager fits into your journey to SOC 2 compliance
Stay ahead of the compliance curve with the help of your Customer Success Manager. Read on to learn how they fit into your SOC 2 journey.
For many companies trying to achieve SOC 2 compliance, keeping up with both the work necessary to get their controls in place along with actually running their business can be quite the juggling act. Luckily, you have a Customer Success Manager (CSM) to help!
So, what exactly does your CSM do? Simply put, your CSM will be your primary point of contact and the main person managing your account throughout the audit process. They are there to help make the roadmap ahead clear, answer questions as you begin your journey, and are then there to keep the audit engagements on track for the years ahead. In order to better understand, let’s touch on the core aspects of a CSM’s role when helping you:
Onboarding
First and foremost, from the moment you sign on to have your audit performed, your CSM is the person who will be scheduling and then holding a kickoff meeting to help set expectations and answer any initial questions you might have as you’re getting started. This meeting walks through the process from start to finish, as well as establishes what the regular communications between you and them will look like moving forward. After the kickoff meeting, they will provide any necessary documents/links to help make sure you have everything to coordinate the audit.
Answering Questions and Scheduling the Audit
Once you’ve gotten your feet wet and have an understanding of what the next steps are, your CSM will be regularly checking in with you to see how things are going as well as provide support for any questions you might have. As you’re going through setting things up, they’ll also be on hand to schedule your audit and coordinate with any readiness platforms you are utilizing to support your SOC 2 compliance.
Supporting the Audit Itself
Once you have the date(s) you want to use for your SOC 2 audit, your CSM will then hand you off to our Audit Associates so that the controls testing can begin. While the CSM will not be performing the audit themselves, they work closely with the Audit team and communicate closely so that the project continues moving forward and you get your report as quickly as possible. If there are any additional evidence pieces needed or clarifications necessary, your CSM will coordinate with the Audit team to make sure these outstanding items are settled.
Continuing and Building Our Partnership
You’ve done it!
You finally have your SOC 2 report in hand! With the audit now complete, your CSM will be one of the first people out the gate to congratulate you; not only that, but they’ll also set expectations as to when we’ll reach out regarding the next report to ensure you won’t have any gaps in your compliance. After a few months, your CSM will reach out to see what your plans for your next SOC 2 report are; in that, they’ll provide a quote as well as coordinate having the Statement of Work (SOW) signed to formalize the engagement. Once you’re signed on, they’re once again there to support you for the various SOC 2 reports to come!
Whether you’re going for your first SOC 2 report ever or you’re a seasoned compliance veteran, it’s important to us that you have every possible tool and aid at your disposal so that you can walk through each step of the audit process with complete confidence that you will succeed.
In all, your CSM is the person to help make this happen; there to help make sure you will come out the other side of this journey with a report that leaves you and your customers satisfied. Whenever you feel stuck, you need only shoot an email over or make a phone call, and your CSM will be there!

Your Guide to SOC 2 Attestation Reports
All the things surrounding SOC 2 reports and attestation can seem a little overwhelming and complicated. We get it; that's why we've created this quick guide to SOC 2 attestation reports with simplified terms and definitions to help you understand the basics.
During a SOC 2 attestation, companies need to use specific criteria to evaluate their services.
All the things surrounding SOC 2 reports and attestation can seem a little overwhelming and complicated. We get it; that's why we've created this quick guide to SOC 2 attestation reports with simplified terms and definitions to help you understand the basics.
A Quick SOC 2 Refresh
You've landed on this article for SOC 2 attestation, so odds are you already know what a SOC 2 report is, but just in case, here's a quick refresh:
What does the S-O-C in 'SOC 2' mean?
- The ‘S-O-C’ stands for System and Organization Controls Number Two.
- SOC 2 is a set of standards developed by the American Institute of Certified Public Accountants (AICPA).
- These standards help businesses evaluate their internal controls and ensure they meet industry best practices regarding information systems management and cyber security.
- Now, onto the basics of SOC 2 attestation reports.
What is a SOC 2 attestation?
A SOC 2 attestation is a third-party assessment of a service organization’s controls relevant to
- Security
- Availability
- Processing Integrity
- Confidentiality
- Privacy
Why do you need a SOC 2 Attestation?
The idea behind a SOC 2 attestation is that companies can demonstrate their commitment to data protection by having their systems reviewed independently. Customers can then make informed decisions about whether it's safe to store sensitive information in the cloud and avoid legal issues down the road.
“The reason for a SOC 2 attestation is that it helps companies and clients know that information held at the service organization is being kept private and secure.”
What does a SOC 2 attestation include?
To assure customers that you're keeping their data safe and secure, you need to show that your company has thought through all aspects of data protection.
Including:
- How do you store customer data?
- Who has access to customer data?
- What measures do you take to protect information against cyberattacks?
What is required During a SOC 2 attestation?
During a SOC 2 attestation, companies are required to use a specific set of criteria to evaluate their services.
These criteria are organized into five trust services categories:
- Security (required)
- Availability (optional)
- Confidentiality (optional)
- Processing Integrity (optional)
- Privacy (optional)
You will also want to ensure that these controls are in place within your systems prior to your SOC 2 attestation with a CPA:
- Network Firewalls
- Two-factor authentication
- Intrusion detection
- Performance monitoring
- Disaster recovery and Incident response procedures
- Security breach management
- Quality assurance
- Process monitoring
- Data encryption
- Access controls (physical and logical)
- Change Management processes
How long does a SOC 2 attestation take?
A SOC 2 Type I (point-in-time) attestation is typically completed in about 4-6 weeks. This may seem like a long time, but remember that it takes more time for complex organizations than for simple ones.
While these variables are essential in determining the duration of your audit, there are also other factors at play:
- If you're working with a new auditor and they don't have much experience on their side yet (for example, if you're their first client), then this will slow down the process somewhat as well. That's why we recommend choosing a CPA specializing in SOC 2 attestations like Johanson Group.
- Some companies may need additional support before providing all the necessary documentation required by SOC 2 auditors; this may add days or weeks to your timeline!
Need to add in SOC 2 Type II (period of time) details. Those audits are a minimum of 3 months the first time and 12 months for subsequent type II audits. Type I tests the design of control, whereas Type II tests both design of controls and their operating effectiveness over a period of time.
How much does a SOC 2 attestation cost?
The cost of a SOC 2 attestation depends on many factors, including:
- Size: Smaller organizations can often complete an audit at a lower cost than larger ones.
- Complexity: Suppose your company uses more complex controls and procedures than other companies. In that case, it will cost more to audit you than if it did not have as much complexity in its controls.
- Type of Service: What type of service is provided by the system being audited? For example, a mobile app for a SaaS start-up may be less expensive than an internal data protection solution for a SaaS healthcare provider due to its more straightforward design and architecture requirements.
- Type of audit (i.e., standard or enhanced): A standard assessment costs less than one that includes additional testing for application-specific vulnerabilities and threats (enhanced.)
The SOC 2 attestation process with Johanson Group
- The first step is to determine whether or not you are eligible for SOC 2 attestation services. If so, we will conduct an initial assessment and provide an estimate based on our findings.
- Once we have reviewed the scope of work and estimated costs, we can begin working with you to develop a detailed plan for implementing security controls into your existing environment. Our goal is always to achieve compliance as efficiently as possible while minimizing disruption to business operations.
In short, a SOC 2 report evaluates whether a service organization's systems and processes meet high standards for security and privacy.
It also assures on behalf of service providers so they can show customers how they use their information responsibly.

Key Differences Between ISO 27001 and 27002
Streamline your payment security controls to protect transactions and maintain merchant trust.
Information security is a pressing concern for organizations.
Cyber threats are on the rise, and more personal information falls into the wrong hands every day.
That's why organizations with an ISMS (information security management system) rely on standards in a set of series called the ISO 27000 series published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Within the ISO 2700 series are the ISO 27001 and 27002.
This article will discuss some key differences between ISO 27001 and 27002 and how each standard helps protect an organization's data from cyber threats.
But before we go into the differences, it's important to note that the ISO 27000 series standards focus on information security. They do not include physical safety, personnel security, or software development requirements.
ISO/IEC 27001 and 27002, what's the difference?
While seemingly similar, the two are just as different. If combined into one singular standard, the compliance criteria would be too complicated to implement and use practically.
To keep it simple, ISO 27001 is a recognized standard for an organization's ISMS. Think of it as a checklist of everything you must complete to receive compliance certification.
ISO 27002 references cyber security, privacy protection, information security, and risk assessment rules.
So, the key differences between the two are:
- Details: ISO 27001 is broad regarding ISMS implementation controls and rules, while ISO 27002 offers detailed recommendations for compliance criteria.
- Applicability: Every ISMS organization and business isn't the same; therefore, following ALL of the recommendations listed in ISO 27002 wouldn't be realistic or needed. ISO 27001 requires organizations must undergo a risk assessment to identify risks but doesn't specify which ones. That is where ISO 27002 comes in handy. Use it as a guide for compliance to prioritize potential risks for your organization.
- Certification: Your organization can only be certified in compliance with ISO 27001 standards. Becoming certified means your organization is fully compliant in your efforts to manage confidential data and information–both your employees and your customers.
Looking for ISO 27001 Compliance Certification? Start now.
What is the benefit of gaining ISO 27001 compliance certification?
ISO 27001 is considered the gold standard for information security management.
It helps organizations implement a system of internal controls to control and monitor their information security risks.
The goal of ISO 27001 is to ensure that an organization maintains a high level of protection for its customers, business partners, employees, and suppliers by implementing an effective ISMS (Information Security Management System).
Organizations can meet this goal by complying with the standards outlined in ISO 27001/27002:
- Risk assessment
- Asset classification and identification
- Control implementation and maintenance
While it's true that you can implement an effective information security program without certification, it's highly recommended to do so because most top-tier customers require certification before they'll consider doing business with you.
This requirement makes sense when you consider that any company possessing sensitive personal or financial data would want to know that their provider has taken all necessary precautions to safeguard this information against cyber attacks. A certificate of ISO 27001 compliance will help ensure this protection.
Examples of how ISO 27001 and ISO 2007 are different:
- The focus of the standards:
The focus of both standards is on information security management, but they take different approaches.
ISO 27001 focuses on information security management and is a generic standard, meaning that the criteria within ISO 27001 can apply to any organization regardless of its sector or industry.
ISO 27002 focuses on data security and is specific; it provides guidance for implementing specific controls within an organization's IT infrastructure (e.g., firewalls).
An organization must determine what type of system or system components will be covered by this standard. For example, a financial institution would focus on entirely different control standards to comply with than a healthcare organization would.
- Process vs. implementation requirements:
In addition to addressing different organizational needs based on sector and industry type, these standards also differ in process requirements versus implementation requirements—that is, how they handle each step required during your risk management program's lifecycle.
Both standards include sections dedicated solely to defining policies explicitly related to risk assessment (ISO/IEC 27000 - 4) and how to implement the suggested measures into daily operations, such as incident response plans (ISO 14701).
Why you need a CPA firm to help your organization with your ISO 27001 or ISO 27002
When managing ISO 27001 or ISO 27002, you need a CPA firm to help your organization with the following:
- A plan:
A solid plan aligned with your business goals and objectives will be essential to ensure success. You will also want to ensure that all key stakeholders are involved in developing this plan.
- Processes and procedures:
Once you have created your plan, it is crucial to define how you will implement it within your organization so everyone knows what's expected of them when carrying out their responsibilities as needed throughout each stage of the ISMS life cycle.
- Knowing the right tools to use for your specific industry and organization:
For example, if your organization is sharing sensitive data across different departments, you will probably need encryption technology like passwords and biometrics authentication systems (fingerprint readers). An experienced CPA in ISO 27001/27002 compliance can suggest the right tools to help you meet compliance criteria.
Information security is laudable. It needs to be done right to make sure that it is effective.
To recap: The difference between 27001 and 27002 is that they both focus on information security but differ in how they go about it.
ISO 27001 focuses more on the processes of an organization, while ISO 27002 focuses more on the products or services that an organization provides.
The best way to protect yourself from cyberattacks is by having a team of professionals who understand both standards to help implement them correctly for your business needs.
Ready to get ISO 27001 certified? Contact Johanson Group today to get started.

.avif)