Input: information on the organisation and its internal and external context. Action: consider all relevant data to identify and describe the internal and external issues and interested-party requirements affecting risk management. Trigger: 27001 requires it for setting security objectives. Output: risk-related issues influencing risk management. The organisation needs a strategic grasp of the issues that can help or hinder the ISMS and of the context bearing on its intended outcomes, preservation of confidentiality, integrity and availability through risk management. It gathers enough detail on its context, interested parties and their requirements (27001 4.1 and 4.2) before assessing any risk (6.1.1), considers all internal and external risk sources, including parties opposed to it such as attackers, whose aims it frustrates through effective controls, and covers in assessment the interfaces with services or activities partly outside the ISMS scope, such as shared facilities, systems or databases and outsourced functions. How other factors are handled depends on the identification and analysis methods chosen; security objectives (6.2) can constrain acceptance criteria and the security policy can rule out treatment options.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.