Blog
When organisations first start ISO 27001, someone in the room inevitably says: “Shouldn’t we just put the whole business in scope?”