Home/ ISO 27001 clauses guide/ Clause 4 · Context of the organization
Requirement 4 · “Plan” phase of the PDCA cycle

Clause 4 — Context of the organization

The first of the seven certifiable clauses, and the one every other clause quietly depends on. Before you can assess risk, set objectives, or define a scope, you have to answer a more basic question: who are we, what surrounds us, and who cares about our information security? Clause 4 forces that answer onto paper — internal and external issues, interested parties and their requirements, and the boundaries of the ISMS itself. Get this wrong, and every downstream clause inherits the mistake: a risk assessment against the wrong scope, objectives that miss what a key customer actually needs, an SoA that does not reflect your real operating environment.

The structure of clause 4

What clause 4 covers

Clause 4 is flat — four requirements, no sub-clauses, much like clauses 8 and 10. 4.1 asks what external and internal issues are relevant to your ISMS. 4.2 asks who your interested parties are and what they actually require of you. 4.3 uses both answers to draw a defensible line around what the ISMS actually covers. 4.4 is the short, almost administrative requirement that ties it together: you must establish, implement, maintain, and continually improve an ISMS built around defined processes and their interactions — which is really the standard telling you clause 4 is not a one-time exercise you file away after certification.

Why it is central

The ISMS scope produced under 4.3 is the boundary every other clause operates inside: it is what clause 6.1.2 assesses risk against, what clause 8.1 controls processes within, and what clause 9.2 audits. An auditor almost always starts by checking the scope statement against reality, because a scope that quietly excludes an inconvenient system undermines the credibility of everything that follows.

The documents that come out of clause 4

  • The ISMS scope statement, available as documented information (4.3)

4.1, 4.2, and 4.4 do not themselves mandate a standalone document, though most organizations record their context analysis and interested-party register as supporting evidence anyway.

Frequently asked questions

Do I need a formal document for 4.1 and 4.2?
Not explicitly, but an auditor will still ask how you identified your context and interested parties, so most organizations keep at least a simple working document — even a short table is enough.
How often should clause 4 be revisited?
There is no fixed frequency, but it should be reviewed whenever the organization changes materially — new markets, new regulations, new major customers — and is commonly revisited as part of the annual management review cycle.

Get your ISMS scope right the first time.

Sentrix helps you document context, interested parties, and scope so every downstream clause starts from solid ground.