Our own servers in Europe · GDPR · Support in your language

Module 1 of 7 · ISO 27001 · Clause 4

Context of the organization

The information security system starts by knowing which assets need protecting and who holds expectations about how they are protected.

Content reviewed on

Internal and external context

Covers the company's activity, its exposure to sector threats and external factors such as applicable data protection regulation.

Interested parties and their requirements

Customers with confidentiality clauses, GDPR, sector regulators, insurers... you need to identify which ones have requirements relevant to the system.

Scope of the ISMS

Defines which assets, locations, systems and processes the information security management system covers, with interfaces and dependencies on third parties.

What an auditor usually asks for

  • A context document reviewed annually
  • A list of interested parties with their security requirements
  • An ISMS scope statement
  • An information asset inventory with an owner

How to cover context in Kimobox

  1. 1Document the ISMS context as just another record in the system.
  2. 2Log interested parties and their security requirements in a versioned table.
  3. 3Build the information asset inventory with an owner and a classification.

The asset inventory stays linked to the processes that use them, not in a separate spreadsheet.

See how the process map works in Kimobox

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO/IEC 27001:2022 — Information security management systems ISO/IEC · 25 October 2022
  2. ISO/IEC 27002:2022 — Information security controls ISO/IEC · February 2022
  3. Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024