isms.coach
← All clauses

Clause 4

Context of the organization

Sub-clauses

  • 4.1 Understanding the organization and its context
  • 4.2 Understanding the needs and expectations of interested parties
  • 4.3 Determining the scope of the ISMS
  • 4.4 Information security management system

Why it matters

This is the clause an auditor reads first — it defines the boundary everything else gets measured against. A vague or copy-pasted scope statement is one of the most common Stage 1 findings.

What it requires

Document the internal and external issues relevant to your ISMS, identify interested parties and what they actually need from you (customers, regulators, investors), and write a specific scope statement — not "our entire company," but which systems, locations, and teams are genuinely in scope.

How a self-led small team handles it

Keep the scope narrow and honest at first. A smaller, accurate scope you can actually defend at audit beats an ambitious one you can't. Revisit interested parties whenever a new type of customer or contract shows up.

Track Clause 4 directly — itsbestpractice has a dedicated Context section built around exactly this clause.

Start your ISMS