4.3 – Determining the Scope of the Information Security Management SystemĬlause 4.3 of the ISO 27001 standard involves setting the scope of your Information Security Management System.
4.2 – Understanding the Needs and Expectations of Interested PartiesĬlause 4.2 of the requirements for ISO 27001 is about ‘Understanding the needs and expectations of your organisation’s interested parties’. We always recommend this is where an organisation starts with its ISO 27001 implementation.
4.1 – Understanding the Organisation and its ContextĬlause 4.1 of the ISO 27001 requirements is about understanding the organisation and its context.