Framework Scope as a Guardrail, Not a Burden
Scope decisions made in a hurry come back as findings. Set framework scope on purpose and write down why each exclusion is safe.
What you'll be able to do
- Decide what's in scope and what's deliberately out
- Justify each exclusion in terms an auditor accepts
- Set the triggers that would bring an excluded system back into scope
- Use scope to focus effort instead of spreading it thin
A scope decision record
What's in it. What is in, what is deliberately out, the justification for each exclusion, and the trigger that would bring it back in.
You build it lesson by lesson, using your own organization, and submit it for your certificate. It's yours to keep and adapt.
Who it's for
GRC leads, compliance managers and anyone defining scope for SOC 2, ISO 27001 or PCI.
What's inside
- Part 1Where the requirement comes from 16 min
- Part 2How small teams and enterprises meet it 14 min
- Part 3The method, step by step 20 min
- Part 4Hands-on lab: small team choose one 60 min
- Part 5Hands-on lab: enterprise choose one 120 min
- Part 6Finish and submit your deliverable 20 min
Built for your size
The requirement is the same everywhere. How you meet it depends on who you have. You pick the lab that matches your organization.
How you earn the certificate
Submit your finished deliverable, which is scored against a published rubric, and pass a short scenario quiz. Your certificate goes to your wallet and can be checked by anyone on the public register.