Clause 4

Context of the organization

Set the foundations: understand your context and interested parties, define the ISMS scope, and establish the ISMS itself.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILClause 4 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Mandatory documents in this clause

  • Scope of the ISMS (4.3)
4.1

Understanding the organization and its context

What it requires: Determine the external and internal issues relevant to your purpose that affect the ISMS’s ability to achieve its intended outcomes.

How to meet it: Keep a short context analysis (for example a SWOT/PESTLE) of issues affecting information security, and review it periodically.

4.2

Needs and expectations of interested parties

What it requires: Identify the interested parties relevant to the ISMS, their relevant requirements, and which of those you will address (including legal, regulatory and contractual obligations).

How to meet it: Maintain an interested-parties register listing each party and its security-relevant requirements.

4.3

Determining the scope of the ISMS

What it requires: Determine the boundaries and applicability of the ISMS, considering 4.1, 4.2, and the interfaces and dependencies with other organisations. The scope must be documented.

How to meet it: Write a clear scope statement naming the products/services, teams, locations, and systems in scope, plus any exclusions and why.

4.4

Information security management system

What it requires: Establish, implement, maintain and continually improve the ISMS, including the processes needed and their interactions.

How to meet it: Treat the ISMS as a living system with defined processes, not a binder. A compliance platform helps keep the processes running.

ISO 27001 policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Looking for the Annex A controls? See all 93 controls. To run these requirements with automation, read how AI manages compliance.