4.1 — Understanding the organization and its context
The requirement that comes before every other requirement: you cannot manage risk to a context you have never actually described.
In plain language
In plain language: 4.1 requires you to identify the external and internal issues that matter to your ability to achieve what you want your ISMS to achieve — things like your regulatory environment, your competitive market, your organizational culture, and your available capabilities.
Position in the standard
Why this requirement exists
A generic ISMS, copied from a template with no reference to your actual situation, tends to miss the risks that matter most to you specifically. A healthcare company and a fintech startup face wildly different external pressures; this requirement forces that difference to actually shape the ISMS instead of being ignored.
Scenario: a company expanding into the European market adopts an ISMS built for its original domestic operations, never updating its context analysis to reflect new GDPR exposure. Risk decisions downstream keep assuming a regulatory environment that no longer fully applies, and the gap surfaces only when a European customer’s security questionnaire asks something the ISMS was never built to answer.
What the standard expects
The standard expects the organization to determine external and internal issues relevant to its purpose and that affect its ability to achieve the intended outcomes of its ISMS. Since Amendment 1:2024, the standard adds an explicit note that the organization shall determine whether climate change is a relevant issue — reflecting growing recognition that climate-related disruption (extreme weather affecting data centre availability, supply chain instability) is a legitimate context factor, not just an environmental, social, and governance talking point.
In practice
- Cover external issues: regulatory and legal requirements, market and competitive conditions, technology trends, and relationships with suppliers or partners.
- Cover internal issues: organizational structure, culture, governance, available resources, and existing capabilities and constraints.
- Explicitly note whether climate-related disruption is a relevant issue for your organization — for many, this will be a brief, documented "not currently significant" rather than a deep analysis, but it must be a considered answer, not an omission.
- Revisit the analysis when the organization changes materially, not just once at certification.
Evidence the auditor will ask for
- A documented context analysis covering external and internal issues.
- Evidence climate change was explicitly considered, even if the conclusion was that it is not currently significant.
- A traceable link between identified issues and later decisions — risk criteria, scope, objectives.
Common pitfalls
- A generic context analysis copied from a template, disconnected from the organization’s actual industry and situation.
- No mention of climate change at all — since Amendment 1:2024, silence on the topic is itself a gap.
- Context analysis performed once at certification and never revisited despite significant organizational change.
Related requirements
4.2 Interested parties
The complementary half of context: who cares, not just what surrounds you.
4.3 ISMS scope
Uses this context analysis directly to draw the ISMS boundary.
Parent link: Clause 4 · Context of the organization
2013 → 2022 mapping
Frequently asked questions
Is the climate change requirement mandatory for everyone?
Does my certification body require re-assessment for Amendment 1:2024?
Build your ISMS around your real context, not a template.
Sentrix helps you document context, including the 2024 climate change consideration, and keep it current as your organization changes.