Has the ISMS scope been documented with boundaries, locations, assets, technologies, and interested parties?
The scope should explain what is included, what is excluded, and why exclusions are justified.
ISO 27001:2022 assessment
The scope should explain what is included, what is excluded, and why exclusions are justified.