For the complete documentation index, see llms.txt. This page is also available as Markdown.

Scopes

Scopes make it possible to define the organizational field of application of compliance projects.

They are used to group organizational units together in order to apply a compliance approach to all or part of the organization.

A scope answers a simple question:

Which organizational entities does this compliance project apply to?


Role of scopes in Dastra

In Dastra, scopes are used exclusively in compliance projects. They make it possible to:

  • precisely target the entities concerned,

  • adapt the requirements, controls and tests to the right level,

  • structure compliance according to the organizational reality.

πŸ‘‰ A scope does not modify the frameworks: it determines where compliance applies, not what applies.


A flexible organizational breakdown

A scope is defined from the organizational units that exist in the workspace.

It can represent:

  • the entire company (e.g. Global)

  • a division or a department (e.g. IT, HR)

  • a site, a subsidiary or a specific activity

Organizational units can be selected individually or in groups, respecting their hierarchy.


Creating a scope

When creating a scope, the user provides:

  • the name of the scope (e.g. Global, IT & Security)

  • an optional description

  • the organizational units included in the scope (mandatory)

πŸ‘‰ A scope must always contain at least one organizational unit.


Example of a scope

πŸ“Œ Example:

  • Name: Global

  • Description: The entire company

  • Organizational units:

    • Global

    • HR

    • IT

    • Factory

    • Sub / Service

This scope can then be selected in a compliance project to indicate that it applies to the entire organization.


Best practices

  • Create a global scope for cross-cutting approaches

  • Create more restricted scopes for targeted projects

  • Reuse scopes across projects to ensure consistency

  • Name scopes in an explicit and business-oriented way


Scopes are selected when creating a compliance project.

They make it possible to:

  • apply the same framework to several entities,

  • track compliance by scope,

  • compare results between different parts of the organization.


Summary

Scopes are an organizational framing tool. They make it possible to align compliance with the actual structure of the company, without adding complexity to the referentials.

Last updated

Was this helpful?