An ISO 27001 scope statement must be specific enough that an external auditor, internal stakeholders, and customers can see exactly which sites, systems, processes, and legal entities are in scope, and which are not. It does not need to list every asset, but it must clearly define boundaries, exclusions, and major dependencies, especially in complex, regulated manufacturing environments.