{"id":1662,"date":"2018-11-29T15:11:11","date_gmt":"2018-11-29T15:11:11","guid":{"rendered":"https:\/\/iso27001.solutions\/?p=1662"},"modified":"2019-03-11T17:54:48","modified_gmt":"2019-03-11T17:54:48","slug":"how-to-define-context-of-the-organization-according-to-iso-27001","status":"publish","type":"post","link":"https:\/\/ismsalliance.com\/trends\/iso-27001-implementation\/how-to-define-context-of-the-organization-according-to-iso-27001\/","title":{"rendered":"How to define context of the organization according to ISO 27001"},"content":{"rendered":"

What must you consider for information security to help achieve business objectives?<\/h2>\n

Since the release of the 2013 revision of ISO 27001, its clause 4.1 requiring the identification of the organizational context has been causing quite some confusion, because it is rather vague.<\/p>\n

To cover this topic, ISO 27001, the leading ISO standard for information security management, requires the definition of the organizational context, referring to ISO 31000, the leading ISO standard for risk management, for detailed guidance.<\/p>\n<\/div>

<\/div>
<\/div>
<\/div>
<\/div><\/div><\/div><\/div><\/div>
<\/a><\/span><\/div><\/div>
<\/div><\/div><\/div><\/div><\/div>
<\/div>
<\/div>
<\/div>

The importance of understanding the organizational context for ISO 27001<\/h2>\n<\/div>
<\/div>
<\/div><\/div>
<\/div>

The organizational context includes external and internal issues relevant to the Information Security Management System<\/a> (ISMS). Besides being a requirement of the standard (clause 4.1), being aware of the organizational context can give an organization a clearer view of the most relevant issues (either positive or negative) for information security, allowing it to properly define the ISMS purpose, devise strategies, and allocate its resources where they will bring better results.<\/p>\n

Examples of internal and external issues to be considered<\/h3>\n

According to ISO 31000 clause 5.3.1, two types of issues should be considered:<\/p>\n

    \n
  1. Internal issues: factors under the direct control of the organization<\/li>\n
  2. External issues: factors an organization has no control over, but that it can anticipate and adapt to<\/li>\n<\/ol>\n

    Examples of internal issues are:<\/strong><\/p>\n