Context of the organisation
The systematic identification of the internal and external issues and the requirements of interested parties that are relevant to an information security management system, and the resulting definition of its scope.
The context of the organisation is the entry point to every management system built on the harmonised structure of the ISO management standards (formerly Annex SL) and is set out in Clause 4 of ISO/IEC 27001. The organisation must first determine the external and internal issues that affect its ability to achieve the intended outcomes of its information security management system. External issues typically include the threat landscape, technological change, market expectations and regulatory requirements such as the NIS2 Directive, DORA or the GDPR. Internal issues cover the organisational structure, governance model, resources and competences, corporate culture, existing IT architecture and strategic objectives.
The second building block, set out in Clause 4.2, is identifying interested parties and their requirements. These include customers, employees and works councils, owners and investors, supervisory and certification bodies, insurers, service providers and suppliers, and public authorities. For each relevant party the organisation records what it expects with regard to information security and which of those expectations the ISMS is intended to address – for example contractual security commitments, statutory reporting and evidence obligations, or audit rights arising from data processing agreements. The 2022 edition additionally requires the organisation to state explicitly which of these requirements will be addressed through the ISMS.
From the context and these requirements the organisation derives the scope of the ISMS under Clause 4.3, which must be available as documented information; Clause 4.4 then requires the system to be established, maintained and continually improved. The context analysis is therefore not a one-off document but a foundation that should be revisited whenever the business model, sites, technologies or legal environment change – and routinely as part of the management review. Comparable analysis is expected by other frameworks as well: BSI Standard 200-1 requires the scope and the general conditions of information security to be determined, and ISO 9001 and ISO 22301 use the same clause structure, which makes an integrated approach easier for organisations running several management systems.
Legal Basis
ISO/IEC 27001:2022 Clause 4 (4.1 to 4.4), ISO/IEC 27003 (guidance), BSI Standard 200-1
Practical Example
A mid-sized IT service provider with 200 employees is preparing for initial ISO/IEC 27001 certification. The information security officer runs two workshops with management, IT, sales and the data protection officer and records the outcome in a context analysis: externally, classification as an important entity under the German NIS2 implementing act, dependence on two cloud providers and the rising number of ransomware attacks in the sector; internally, distributed sites, a tight security budget and a planned cloud migration. A second table captures interested parties and their requirements – key accounts with contractually agreed recovery times, the works council with requirements on logging, and the supervisory authority with reporting and evidence obligations. On this basis the scope is set to data centre operations and managed services at two sites, and it is reassessed in the annual management review.