Contractor or employee? Understanding the new gateway test in NZ law
For businesses that use contractors, it’s important to understand what’s changed and what to do...
If your company is ISO 27001 certified, understanding the internal and external issues relevant to your ISMS (Information Security Management System) is crucial. Identifying these issues affects the system’s ability to achieve its intended outcomes. Recognising your organisational context helps provide a clearer view of both positive and negative influences on information security, allowing you to allocate resources more effectively.
Understanding the organisation’s context is also a requirement under clause 4.1 of the ISO 27001 standard. Below, we explore the internal and external contexts that may influence an organisation’s ability to achieve its intended outcomes.
Internal issues involve factors within the direct control of a company. These include:
External issues are factors outside an organisation that impact its progress or success. While an organisation cannot control these factors, it can adapt to them. They include:
Under ISO/IEC 27001, you are not required to document the context of the organisation in a separate document. However, you must document information on specific issues. For external issues, you should document your information security goals, outcomes of risk assessments, information assets, and the competence of your staff. You must also document the relevant regulatory, contractual, legislative, and statutory requirements.