Context of the Organisation (ISO 27001)

Requirement to identify internal/external factors and stakeholders that influence the ISMS.

Context of the Organisation is a foundational requirement in ISO 27001 that mandates organisations to identify and analyse internal and external factors affecting their Information Security Management System (ISMS). This includes understanding the organisation's purpose, scope, stakeholders, and regulatory environment.

Organisations must document their context, including factors that could positively or negatively impact ISMS effectiveness. This understanding informs risk assessments, control selection, and the overall security strategy. Regular review ensures the ISMS remains relevant and effective.