Chapter 5
05Context and Scope: Know Where You Stand
“A vague scope means a system that protects everything in theory and nothing in practice.”
Clause 4 of the standard begins with a question that sounds simple: who are we, and what surrounds us? Before choosing a single control, we need to understand the internal and external issues that affect our ability to protect information, the parties who care about our security, and the boundaries within which the system will operate.


Text in this figure
Internal issues · Clause 4.1 · Culture, structure · Capabilities, resources · Systems and tools · Interested parties · Clause 4.2 · Clients, freelancers · Regulators, partners · Staff, investors · External issues · Clause 4.1 · Laws, regulations · Threat landscape · Market, technology · Scope (Clause 4.3) · What the system protects: sites, systems, teams and assets.. and what lies outside, and why · Figure 6
Internal and External Issues
- Internal: Team size, the proportion of freelancers, approved cloud tools, technical maturity, and a culture of working under deadline pressure.
- External: Clients’ security requirements, data protection laws in every market we serve, the threat landscape, and dependence on external platforms such as storage and AI services.
- Climate: The 2024 amendment to the standard explicitly requires considering whether climate change is a relevant issue, such as the effect of heatwaves or floods on data centres and filming locations.
Interested Parties and Their Requirements
Interested parties are everyone affected by, or affecting, our security: clients who entrust us with their campaigns and data, employees and freelancers, suppliers, regulators, and the public who could be harmed by a leak or a fake post. Each has requirements; some are written in a contract or law, and some are an implicit expectation that their files are safe.
Defining the Scope
The scope is a short document setting out what the system includes: sites, teams, services, systems and interfaces with external parties. An agency can start with a limited scope, such as its brand design service alone, and then expand it. What matters is that the scope is honest: it must not exclude the riskiest part to make certification easier.
From the Field
The scope most likely to fail an audit is the one that excludes “the freelancer team” or “AI tools” on the grounds that they are outside the organisation, while the most valuable client files pass through them every day.
Context defines scope, scope defines risks, and risks define controls.
Lessons Learned
- 1Understanding internal and external issues comes before any control.
- 2Every interested party has requirements, written or implicit.
- 3An honest scope includes the riskiest parts, not the easiest to audit.
- 4Climate change has been an explicit item in the context review since 2024.
Tip: use ← → to move between sections.

