SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Clauses 4.1 and 4.2 in a software development organization

  Quote
Guest
Guest user Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Clauses 4.1 and 4.2 in a software development organization

 The only issue I am facing with new version is for clause number 4.1 "context or organization" and clause number 4.2 "interested parties concern". It will be very helpful if you explain with some example for a software development organization.
0 0

Assign topic to the user

ISO 27001 PROCEDURE FOR IDENTIFICATION OF REQUIREMENTS

Basics of identification of interested parties and their requirements.

ISO 27001 PROCEDURE FOR IDENTIFICATION OF REQUIREMENTS

Basics of identification of interested parties and their requirements.

Guest
AntonioS Jan 12, 2016

Your question is very common, and these are points where ISO 27001 has been aligned with other ISOs, but don’t worry we can help you to understand this point. Regarding to the context, please read this article, will be very helpful for you “Explanation of ISO 27001:2013 clause 4.1 (Understanding the organization)” : https://advisera.com/27001academy/knowledgebase/how-to-define-context-of-the-organization-according-to-iso-27001/. For example, for internal issues you must to make sure that your information security objectives are aligned with the business strategy. In your business: improve the security of the source code establishing security controls.
 
Regarding to the interested parties, please read this article “How to identify interested parties according to ISO 27001 and ISO 223 01": https://advisera.com/27001academy/knowledgebase/how-to-identify-interested-parties-according-to-iso-27001-and-iso-22301//. In your case, an interested party can be developers, the Internet Service Provider, etc.
 
Please let us know if you need more help.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics