How to Write an ISO 27001 ISMS Scope Statement (Clause 4.3 Template + Example)
What ISO 27001 clause 4.3 requires your ISMS scope statement to cover, common scoping patterns and tradeoffs, and a worked SME example.
NIS2 compliance guides and resources
What ISO 27001 clause 4.3 requires your ISMS scope statement to cover, common scoping patterns and tradeoffs, and a worked SME example.
The exact Annex A controls (5.19-5.23) an ISO 27001 supplier security policy must cover, NIS2 overlap, risk tiering, and a free policy skeleton.
What ISO 27001’s business continuity policy actually requires (A.5.29, A.5.30, A.8.13, A.8.14), how it differs from ISO 22301, plus a free policy skeleton.
The exact Annex A controls an ISO 27001 incident response policy must cover, how NIS2’s 24/72-hour clock differs, plus a free policy skeleton.
Which ISO 27001 Annex A controls your access control policy must cover, how NIS2 Article 21(2)(i) already helps, plus a free policy skeleton.
What ISO 27001 clause 9.2 requires from an internal audit, how it differs from a gap analysis, and a risk-based checklist by clause and Annex A control.
What an ISO 27001 Statement of Applicability actually is, how it’s built from your risk assessment, and a worked example across 5 Annex A controls.
NIS2 compliance and ISO 27001 overlap 70-80% at the foundation. Here is the real business case, what transfers, what is new, and when to pursue it.
What ISO 27001:2022 actually requires, what certification costs and takes, and why NIS2-compliant companies are already 70-80% of the way there.
PIM and Conditional Access alone don’t satisfy NIS2 access control. See what Entra ID covers under CIR Section 11 — and the licensing gap most tenants miss.