Clause 4.1 Understanding the organization and its context
Clause 4.1 in ISO 27001:2022 (ISO/IEC 27001:2022). All ISO 27001:2022 controls held. Open ISO 27001:2022 on the standards site.
The control as we hold it
Understanding the organization and its context. The organization has to identify the internal and external issues that bear on its purpose and that influence whether its ISMS can deliver the outcomes intended for it. The note links this to establishing external and internal context in ISO 31000:2018, 5.4.1. Amendment 1:2024 adds that the organization must decide whether climate change is a relevant issue (the amendment's wording is held only as quoted in a third-party implementation guide).
Reviewed and closest counterparts in the other frameworks
We hold no cross-framework row for Clause 4.1 yet. The reviewed pairs page lists the released pairs and their coverage.
What an auditor commonly asks for
General guidance for this control area (domain: Clause 4), in our words, not a statement of the standard and not binding on an assessor.
- A documented analysis of internal and external issues (for example a PESTLE or SWOT) tied to the ISMS's intended outcomes, with the date of last review
- The recorded decision on whether climate change is a relevant issue, since Amendment 1:2024
- Evidence that the issues fed the scope (4.3) and the risk and opportunity planning in 6.1.1
- Management review minutes showing changes in issues were considered (9.3.2 b)