ISO/IEC 27003:2017
Context of the organization – ISO/IEC 27003:2017

ISO/IEC 27003:2017 ISO27003-4.1: Understanding the organization and its context

The organization works out which outside and inside issues bear on its purpose and on whether the ISMS can deliver what it is meant to deliver. Explanation: this self-analysis is continuous and serves three ends: fixing the ISMS scope, finding risks and opportunities, and keeping the ISMS in step as circumstances shift. Outside issues, beyond the organization's control, can be social and cultural; political, legal, normative and regulatory; financial and macroeconomic; technological; natural; and competitive (illustrations: legal consequences of an outsourced IT service, exposure to fire, flood or earthquake, advances in attack tools and cryptography, demand for the organization's services). Inside issues, within its control, can be culture; policies, objectives and strategies; governance, structure, roles and responsibilities; adopted standards, guidelines and models; contracts that directly affect in-scope processes; processes and procedures; capabilities in resources and knowledge; the physical infrastructure and its surroundings; information systems and the flows of information between them; decision making, both formal and informal; and earlier audit and risk assessment results. Its results are used by the scope clause (4.3), planning (6.1) and management review (9.3). Guidance: starting from the mission or business plan and the ISMS's intended outcomes, examine the environment and the internal aspects, asking of each category how it affects the information security objectives (for instance, reuse existing governance by sharing management review and audit with other management systems, align security objectives with business objectives, and map information flows between systems in enough detail); revisit the issues and their effect on scope, constraints and requirements regularly. Recording this is needed only as far as the organization itself judges useful for effectiveness, per 7.5.1 b) of the 2013 requirements. Also noted: the organization may be a legal or administrative entity, a part of one, a group of them, or a group of parts of them.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 15 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 23894:2023 · 2 controls

  • 23894-5.4.1 Understanding Organization and Context
  • 5.4.1 Understanding the organization and its context

ISO 14001:2015 · 1 control

  • 4.1 Understanding the organization and its context

ISO 14004:2016 · 1 control

  • 4.1 Understanding the organization and its context

ISO 22000:2018 · 1 control

  • 4.1 Understanding the organization and its context

ISO 22301:2019 · 1 control

  • 4.1 Understanding the organization and its context

ISO 27701:2019 · 1 control

  • 5.2.1 Understanding the organization and its context

ISO 31000:2018 · 1 control

  • 5.4.1 Understanding the organization and its context

ISO 37001:2016 · 1 control

  • 4.1 4.1 Understanding the organization and its context

ISO 37301:2021 · 1 control

  • 4.1 Understanding the organization and its context

ISO 45001:2018 · 1 control

  • 4.1 Understanding the organization and its context
  • 4.1 Understanding the organization and its context

ISO 55001:2014 · 1 control

  • 4.1 Understanding the organization and its context

ISO 9001:2015 · 1 control

  • 4.1 Understanding the organization and its context

ISO/IEC 42001:2023 · 1 control

  • 4.1 Understanding the organization and its context

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Context of the organization – ISO/IEC 27003:2017

Query this from an agent

The graph holds this control, the 15 it maps to, and the evidence behind each claim, over MCP and REST.