Awakening Security

Request the PDF

Enter your email and we will send you a code; your request is then recorded at once, and once I have reviewed it a link to download your copy reaches your email.

By continuing, your email and progress are kept in your account. Privacy

* The file is for your own reading; sharing follows the terms of use, and commercial use is not permitted.

Reading progress
0 of 34 sections read
7 / 34

Chapter 5

05Context and Scope: Know Where You Stand

2 min read7 of 34Read it in the book · page 34

“A vague scope means a system that protects everything in theory and nothing in practice.”

Clause 4 of the standard begins with a question that sounds simple: who are we, and what surrounds us? Before choosing a single control, we need to understand the internal and external issues that affect our ability to protect information, the parties who care about our security, and the boundaries within which the system will operate.

Context defines scope: internal and external issues and interested partiesContext defines scope: internal and external issues and interested parties
Context defines scope: internal and external issues and interested parties
Text in this figure

Internal issues · Clause 4.1 · Culture, structure · Capabilities, resources · Systems and tools · Interested parties · Clause 4.2 · Clients, freelancers · Regulators, partners · Staff, investors · External issues · Clause 4.1 · Laws, regulations · Threat landscape · Market, technology · Scope (Clause 4.3) · What the system protects: sites, systems, teams and assets.. and what lies outside, and why · Figure 6

Internal and External Issues

  • Internal: Team size, the proportion of freelancers, approved cloud tools, technical maturity, and a culture of working under deadline pressure.
  • External: Clients’ security requirements, data protection laws in every market we serve, the threat landscape, and dependence on external platforms such as storage and AI services.
  • Climate: The 2024 amendment to the standard explicitly requires considering whether climate change is a relevant issue, such as the effect of heatwaves or floods on data centres and filming locations.

Interested Parties and Their Requirements

Interested parties are everyone affected by, or affecting, our security: clients who entrust us with their campaigns and data, employees and freelancers, suppliers, regulators, and the public who could be harmed by a leak or a fake post. Each has requirements; some are written in a contract or law, and some are an implicit expectation that their files are safe.

Defining the Scope

The scope is a short document setting out what the system includes: sites, teams, services, systems and interfaces with external parties. An agency can start with a limited scope, such as its brand design service alone, and then expand it. What matters is that the scope is honest: it must not exclude the riskiest part to make certification easier.

From the Field

The scope most likely to fail an audit is the one that excludes “the freelancer team” or “AI tools” on the grounds that they are outside the organisation, while the most valuable client files pass through them every day.

Context defines scope, scope defines risks, and risks define controls.

Lessons Learned

  1. 1Understanding internal and external issues comes before any control.
  2. 2Every interested party has requirements, written or implicit.
  3. 3An honest scope includes the riskiest parts, not the easiest to audit.
  4. 4Climate change has been an explicit item in the context review since 2024.

Tip: use ← → to move between sections.