The organization works out which outside and inside issues bear on its purpose and on whether the ISMS can deliver what it is meant to deliver. Explanation: this self-analysis is continuous and serves three ends: fixing the ISMS scope, finding risks and opportunities, and keeping the ISMS in step as circumstances shift. Outside issues, beyond the organization's control, can be social and cultural; political, legal, normative and regulatory; financial and macroeconomic; technological; natural; and competitive (illustrations: legal consequences of an outsourced IT service, exposure to fire, flood or earthquake, advances in attack tools and cryptography, demand for the organization's services). Inside issues, within its control, can be culture; policies, objectives and strategies; governance, structure, roles and responsibilities; adopted standards, guidelines and models; contracts that directly affect in-scope processes; processes and procedures; capabilities in resources and knowledge; the physical infrastructure and its surroundings; information systems and the flows of information between them; decision making, both formal and informal; and earlier audit and risk assessment results. Its results are used by the scope clause (4.3), planning (6.1) and management review (9.3). Guidance: starting from the mission or business plan and the ISMS's intended outcomes, examine the environment and the internal aspects, asking of each category how it affects the information security objectives (for instance, reuse existing governance by sharing management review and audit with other management systems, align security objectives with business objectives, and map information flows between systems in enough detail); revisit the issues and their effect on scope, constraints and requirements regularly. Recording this is needed only as far as the organization itself judges useful for effectiveness, per 7.5.1 b) of the 2013 requirements. Also noted: the organization may be a legal or administrative entity, a part of one, a group of them, or a group of parts of them.
This control maps to 15 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 15 it maps to, and the evidence behind each claim, over MCP and REST.