"The scope statement is an important statement for any organizations iso 27001 certification as it reflects the business and supporting functions that support the information security management system (ISMS).
A scope statement generally has the following 4 parts:
Part 1: About the business, the sentence looks like:
information security management system (ISMS) applies to the delivery of [Software as a service (SAAS)] OR [business process outsourcing].
Part 2 – Industries that you serve, the sentence may look like:
The services cater to the healthcare industry.
Part 3 – Internal teams or functions:
ISMS is supported by internal teams such as Product Management, Application Development, Cloud Operations, DevOps, IT Operations, Human Resource, Legal, Procurement, physical security and business development.
Here you write functions as per the organization structure, all teams that participated.
Part 4 – Reference to Statement of Applicability (SOA)
This is as per Statement of Applicability (SOA) version 1.0
Note that the SOA is where all the applicable and not applicable controls are listed.