How to document the external and internal context of the organisation
Assign topic to the user
Debasish,
In my opinion, it is not necessary to write a separate document for the context of the organization (clause 4.1 in ISO 27001:2013) - you can cover it through these documents:
- Business plan (if you have one)
- ISMS Scope
- List of requirements from your interested parties
- Risk assessment report
Comment as guest or Sign in
Jan 12, 2016

