ISO 27005:2022
Leveraging related ISMS processes – ISO 27005:2022

ISO 27005:2022 10.1: Context of the organization

Input: information on the organisation and its internal and external context. Action: consider all relevant data to identify and describe the internal and external issues and interested-party requirements affecting risk management. Trigger: 27001 requires it for setting security objectives. Output: risk-related issues influencing risk management. The organisation needs a strategic grasp of the issues that can help or hinder the ISMS and of the context bearing on its intended outcomes, preservation of confidentiality, integrity and availability through risk management. It gathers enough detail on its context, interested parties and their requirements (27001 4.1 and 4.2) before assessing any risk (6.1.1), considers all internal and external risk sources, including parties opposed to it such as attackers, whose aims it frustrates through effective controls, and covers in assessment the interfaces with services or activities partly outside the ISMS scope, such as shared facilities, systems or databases and outsourced functions. How other factors are handled depends on the identification and analysis methods chosen; security objectives (6.2) can constrain acceptance criteria and the security policy can rule out treatment options.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • BS65000-4.1 Context of the Organization

ISO 27701:2019 · 1 control

  • 5.2 Context of the organization

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Leveraging related ISMS processes – ISO 27005:2022

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.