Solutions The best route to security compliance
Platform A powerful suite of ISMS features
Resources Everything you need to know
Knowledge Base Learn more about infosec
Company Security and customers first

ISO 27001 Clause 4

Read about the requirements for ISO 27001 Clause 4 that organisations should be aware of when researching, establishing, implementing, maintaining, and continually improving their information security management system (ISMS).

Navigate through the following subclauses to more effectively understand the details of each step of the process.

ISO 27001 Clause 4.1

This clause covers understanding the internal and external issues that your organisation should consider in the context of creating an ISMS. We provide some examples of both types of issues to look out for.

ISO 27001 Clause 4.2

The second clause addresses understanding the needs and expectations of interested parties, including examples of how to identify these parties and stakeholder mapping to identify their needs.

ISO 27001 Clause 4.3

This clause focuses on taking the learnings from clauses 4.1 and 4.2 and using them to determine what is in and out of the scope of your ISMS.

ISO 27001 Clause 4.4

This clause simply states the requirements of organisations in terms of their ISMS: establishing, implementing, maintaining, and continually improving their information security management system.