Testing
Scope
Also called: testing scope, in scope, assessment boundary
Scope is the explicit list of systems, applications, networks, accounts and techniques included in a security assessment, and everything excluded from it. It determines what the resulting report can be used to claim.
Scope is where audit value is won or lost. A report whose scope does not cover the system in the SOC 2 system description or the ISO 27001 Statement of Applicability is evidence for something, but not for that audit.
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.