ISO 27001 guide · Plan
Clause 4 — Context of the organization
ISO 27001:2022 clause 4 covers your context, your interested parties and the ISMS scope: the foundation every other clause of the standard builds on.
By Sentrix · Published 2026-07-16
The first of the seven certifiable clauses, and the one every other clause quietly depends on. Before you can assess risk, set objectives, or define a scope, you have to answer a more basic question: who are we, what surrounds us, and who cares about our information security? Clause 4 forces that answer onto paper — internal and external issues, interested parties and their requirements, and the boundaries of the ISMS itself. Get this wrong, and every downstream clause inherits the mistake: a risk assessment against the wrong scope, objectives that miss what a key customer actually needs, an SoA that does not reflect your real operating environment.
What clause 4 covers
Clause 4 is flat — four requirements, no sub-clauses, much like clauses 8 and 10. 4.1 asks what external and internal issues are relevant to your ISMS. 4.2 asks who your interested parties are and what they actually require of you. 4.3 uses both answers to draw a defensible line around what the ISMS actually covers. 4.4 is the short, almost administrative requirement that ties it together: you must establish, implement, maintain, and continually improve an ISMS built around defined processes and their interactions — which is really the standard telling you clause 4 is not a one-time exercise you file away after certification.
Why it is central
The ISMS scope produced under 4.3 is the boundary every other clause operates inside: it is what clause 6.1.2 assesses risk against, what clause 8.1 controls processes within, and what clause 9.2 audits. An auditor almost always starts by checking the scope statement against reality, because a scope that quietly excludes an inconvenient system undermines the credibility of everything that follows.
The documents that come out of clause 4
- The ISMS scope statement, available as documented information (4.3)
4.1, 4.2, and 4.4 do not themselves mandate a standalone document, though most organizations record their context analysis and interested-party register as supporting evidence anyway.
Support
Need hands-on support scoping your ISMS? See the ISO 27001 compliance service or go back to the 7-clause guide.
Sources
Frequently asked questions
- Do I need a formal document for 4.1 and 4.2?
- Not explicitly: only 4.3 requires the scope to be available as documented information. But an auditor will still ask how you identified your context and interested parties, so most organizations keep at least a simple working document — even a short table is enough — and record it as supporting evidence for the rest of the ISMS.
- How often should clause 4 be revisited?
- There is no fixed frequency in the standard, but it should be reviewed whenever the organization changes materially — new markets, new regulations, new major customers — and it is commonly revisited as part of the annual management review cycle. Sub-clause 4.4 is a reminder that the ISMS must be maintained and continually improved, not filed away after certification.
- Why does the ISMS scope matter so much?
- The scope produced under 4.3 is the boundary every other clause operates inside: it is what 6.1.2 assesses risk against, what 8.1 controls processes within, and what 9.2 audits. An auditor almost always starts by checking the scope statement against reality, because a scope that quietly excludes an inconvenient system undermines the credibility of everything that follows.
Related pages
ISO 27001 guide · Clause 4
4.1 — Understanding the organization and its context
ISO 27001:2022 sub-clause 4.1 requires identifying the external and internal issues relevant to your ISMS, including, since Amendment 1:2024, climate change.
ISO 27001 guide · Clause 4
4.2 — Needs and expectations of interested parties
ISO 27001:2022 sub-clause 4.2 requires identifying interested parties and their requirements, and, new in 2022, deciding which ones the ISMS will address.
ISO 27001 guide · Clause 4
4.3 — Determining the scope of the ISMS
ISO 27001:2022 sub-clause 4.3 requires determining the boundaries and applicability of the ISMS to establish its scope, plus the evidence auditors request.
ISO 27001 guide · Clause 4
4.4 — Information security management system
ISO 27001:2022 sub-clause 4.4 requires establishing, implementing, maintaining and improving an ISMS built around defined processes and their interactions.
Let's talk about your compliance program.
Last updated: 2026-09-17
