# Clause 4 - Context of the Organisation

The 4th clause of ISO 27001 is "Context of the organisation". This clause requires organisations to determine the internal and external factors that may impact the security of their information and the effectiveness of their ISMS.

Specifically, the clause requires organisations to identify their interested parties (such as customers, suppliers, and regulators) and their requirements related to information security, as well as the scope of the ISMS (i.e., the boundaries of the information security management system).

Organisations must also identify the risks and opportunities related to information security that may arise from the internal and external context, and ensure that the ISMS takes these into account. This includes considering the organisation's culture, values, and operating environment, as well as legal, regulatory, and contractual requirements related to information security.

The purpose of this clause is to ensure that the ISMS is designed to be appropriate and effective for the specific organisation and its context, and that the organisation's leadership is fully aware of the risks and opportunities related to information security. By doing so, organisations can better manage their information security risks and protect their sensitive information from unauthorised access, use, or disclosure.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://manual.harpe.io/start/iso27001-2013-wiki/the-clauses/clause-4-context-of-the-organisation.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
