Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

ISMS Scope

← Back to Glossary
By NHI Mgmt Group Updated August 24, 2026 Domain: Governance, Ownership & Risk

The Information Security Management System scope defines which information processing activities are covered by ISO 27001 controls. For AI, scope is not limited by tool type. If company information is handled in prompts, uploads, connectors, or agent workflows, those activities belong inside the ISMS and must be risk assessed and controlled.

Expanded Definition

ISMS scope is the boundary that determines which people, processes, systems, data flows, and third-party dependencies are governed by the Information Security Management System. Under ISO/IEC 27001:2022 Information Security Management, scope is not a branding exercise or a list of approved applications. It is the operational definition of what must be risk assessed, controlled, monitored, and improved. For NHI and AI-enabled environments, that boundary must include where secrets, tokens, certificates, prompts, connectors, automation pipelines, and agent workflows are used to process company information.

Definitions vary across vendors when AI tooling is involved, but the security principle stays the same: if an activity can affect confidentiality, integrity, or availability, it belongs in scope unless there is a defensible exclusion. Good scoping also clarifies interfaces with suppliers and shared services, which is essential when a cloud app, model host, or workflow orchestrator can act on enterprise data. The ISO standard provides the management system structure, while internal scope statements translate that structure into a reviewable boundary. The most common misapplication is treating a tool inventory as the ISMS scope, which occurs when teams exclude prompts, connectors, or agent actions simply because they are embedded inside a platform rather than a standalone system.

Examples and Use Cases

Implementing ISMS scope rigorously often introduces governance friction, because broader boundaries expand assessment effort, evidence collection, and supplier oversight, requiring organisations to weigh assurance against administrative load.

  • A SaaS deployment is included in scope because staff upload regulated customer records and the provider stores logs, exports, and access records that affect control coverage.
  • An AI assistant is brought into scope because it can read internal documents, generate outputs from sensitive content, and call OWASP Non-Human Identity Top 10 relevant automation identities that hold access tokens.
  • A data pipeline is scoped because it moves HR, finance, or security data between systems and can alter integrity through misconfiguration or unauthorized changes.
  • A managed service is partially in scope where supplier personnel administer logging, backups, or identity components that support the ISMS boundary.
  • A prompt engineering workflow is included because prompts and retrieved context may expose confidential information, even if the underlying model is externally hosted.

These examples show why scope is a control decision, not a procurement label. A narrow scope can simplify certification preparation, but it becomes unsafe if it omits systems that actually handle sensitive information. For guidance on management system expectations, ISO/IEC 27001:2022 Information Security Management is the primary reference point, while organisational scoping should trace each asset to a business process, data category, and risk owner.

Why It Matters for Security Teams

Security teams depend on ISMS scope because every later decision, from risk assessment to internal audit, rests on that boundary. If the scope is wrong, controls are applied inconsistently, incidents land in gaps, and leadership receives false assurance that key systems are protected. This is especially important in AI and identity-rich environments, where non-human identities, API keys, service accounts, and agent permissions can create hidden access paths outside traditional application inventories.

Scope also determines what evidence must be collected during certification, supplier review, and recurring management review. When an organisation cannot show why a connector, token store, or agent workflow was excluded, the exclusion weakens the credibility of the entire ISMS. A well-written scope statement makes it possible to connect risks, controls, and ownership across on-premises systems, cloud services, and automation layers. Practitioners should treat scope as a living governance artifact that changes when business processes, data handling, or integrations change.

Organisations typically encounter the real cost of poor scoping only after an audit finding, a breach, or a failed access review, at which point ISMS scope becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST AI RMF set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022Clause 4.3Clause 4.3 defines the ISMS scope and requires its boundaries and applicability to be established.
NIST CSF 2.0ID.GV-1Governance requires security roles, responsibilities, and oversight to be established and communicated.
NIST SP 800-53 Rev 5PM-5The program management control family supports enterprise-wide security program scope and documentation.
NIST SP 800-63IAL2Identity assurance becomes relevant when scoped workflows handle authoritative identity data or onboarding.
NIST AI RMFGOVERN 1.1AI risk governance starts by defining which AI uses are covered by the organisation's controls.

Define the ISMS boundary by process, asset, and dependency, then keep exclusions justified and documented.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org