Internal and external context
Covers the company's activity, its exposure to sector threats and external factors such as applicable data protection regulation.
Interested parties and their requirements
Customers with confidentiality clauses, GDPR, sector regulators, insurers... you need to identify which ones have requirements relevant to the system.
Scope of the ISMS
Defines which assets, locations, systems and processes the information security management system covers, with interfaces and dependencies on third parties.
What an auditor usually asks for
- A context document reviewed annually
- A list of interested parties with their security requirements
- An ISMS scope statement
- An information asset inventory with an owner
How to cover context in Kimobox
- 1Document the ISMS context as just another record in the system.
- 2Log interested parties and their security requirements in a versioned table.
- 3Build the information asset inventory with an owner and a classification.
The asset inventory stays linked to the processes that use them, not in a separate spreadsheet.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- ISO/IEC 27001:2022 — Information security management systems ISO/IEC · 25 October 2022
- ISO/IEC 27002:2022 — Information security controls ISO/IEC · February 2022
- Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024