Question
What are "Scope" and "Statement of Applicability" (SoA) in the context of ISO 27001 certification?
Answer
The Scope defines what part of the organization the ISMS covers, and the SoA lists which ISO 27002 controls apply — together they define the certification boundary.
Scope — the area the ISMS applies to:
- Entire company
- A single department
- A specific location
- Part of the infrastructure (e.g., the DMZ)
Statement of Applicability (SoA) — lists which controls from ISO 27002 the ISMS addresses, with justification for any exclusions.
Why this matters: A company with an ISO 27001 certificate might only have certified a small part of its operations. Always check the scope! A certificate for "the DMZ" doesn't mean the entire organization meets the standard.
Tip: Think of it like this — Scope = "where does the ISMS apply?", SoA = "what controls does it include?"
Note saved — thanks!
Question
How is the layer model (Schichtenmodell) of the IT-Grundschutz-Kompendium structured?
Answer
Ten block families in two groups: process blocks (ISMS, ORP, CON, OPS, DER) and system blocks (IND, APP, SYS, NET, INF) — a "function-oriented" structure.
* The Schichtenmodell — process Bausteine (ISMS, ORP, CON, OPS, DER) and system Bausteine (IND, APP, SYS, NET, INF), with each Baustein decomposing into sub-Bausteine (e.g. SYS → SYS.1 Server → SYS.1.1 General server). *
The block families:
Process blocks (Prozess-Bausteine) — organizational/overarching:
| Code | Meaning |
|---|---|
| ISMS | Security management |
| ORP | Organization & personnel |
| CON | Concepts & procedures |
| OPS | Operational security aspects |
| DER | Detection & reaction (to security incidents) |
System blocks (System-Bausteine) — concrete technology:
| Code | Meaning |
|---|---|
| IND | Industrial IT (SCADA etc.) |
| APP | Applications |
| SYS | IT systems and components |
| NET | Networks |
| INF | Physical security / infrastructure |
The old catalogs were system-oriented; the new model is function-oriented: overarching/process aspects are separated from systems, and responsibilities are bundled — another deliberate step toward the structure of ISO 27001.
Tip: Mnemonic for the process side: "ISMS ORganizes CONcepts, OPerates, DEtects & Reacts."
Go deeper:
Lerneinheit 5.2: Schichtenmodell (BSI Online-Kurs) — Erklärt die Prozess- und System-Bausteinfamilien des Schichtenmodells.
IT-Grundschutz-Kompendium (BSI) — Originalstruktur der zehn Schichten und Bausteine.
Note saved — thanks!