ExportableProof — Routines today. Proof tomorrow.

System

ISMS Scope Statement

This statement freezes the ISMS boundary for a software company so an auditor can see what is in, what is out, who approved exclusions and which interfaces carry shared responsibility. It is not the organization statement, not the SoA and not the asset inventory.

Back to demo

OSCAL source · ISS

{
  "artifactId": "ISS",
  "iso": [
    "4.3",
    "4.1",
    "4.2"
  ],
  "catalog": [
    {
      "iso": "4.3",
      "oscalId": "iso27001-4.3",
      "title": "Determining the scope of the ISMS",
      "className": "iso27001-clause",
      "group": "Context of the organization"
    },
    {
      "iso": "4.1",
      "oscalId": "iso27001-4.1",
      "title": "Understanding the organization and its context",
      "className": "iso27001-clause",
      "group": "Context of the organization"
    },
    {
      "iso": "4.2",
      "oscalId": "iso27001-4.2",
      "title": "Understanding the needs and expectations of interested parties",
      "className": "iso27001-clause",
      "group": "Context of the organization"
    }
  ],
  "profileAlters": [
    {
      "control-id": "iso27001-4.1",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-4.2",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-4.3",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "ISO/IEC 27001:2022 management-system clause. Always in the certification scope; not subject to Annex A SoA exclusion."
            },
            {
              "name": "implementation-status",
              "value": "always-in-scope"
            }
          ]
        }
      ]
    }
  ],
  "components": [],
  "sspImplementedRequirements": []
}

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…