Sub-clauses
- 4.1 Understanding the organization and its context
- 4.2 Understanding the needs and expectations of interested parties
- 4.3 Determining the scope of the ISMS
- 4.4 Information security management system
Why it matters
This is the clause an auditor reads first — it defines the boundary everything else gets measured against. A vague or copy-pasted scope statement is one of the most common Stage 1 findings.
What it requires
Document the internal and external issues relevant to your ISMS, identify interested parties and what they actually need from you (customers, regulators, investors), and write a specific scope statement — not "our entire company," but which systems, locations, and teams are genuinely in scope.
How a self-led small team handles it
Keep the scope narrow and honest at first. A smaller, accurate scope you can actually defend at audit beats an ambitious one you can't. Revisit interested parties whenever a new type of customer or contract shows up.
Track Clause 4 directly — itsbestpractice has a dedicated Context section built around exactly this clause.
Start your ISMS