nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #142

Which one of the following options is the definition of the context of an organisation?

The correct answer is C. A combination of internal and external issues that can have an effect on an organisation's. The context of the organisation is the business environment in which the organisation operates and defines its information security management system (ISMS). It includes the internal and external factors and conditions that can influence the organisation's information security…

Understanding ISO/IEC 27001 Requirements

Question

Which one of the following options is the definition of the context of an organisation?

Options

  • AThe control of internal and external issues that can have an effect on an organisation's desire to
  • BComplexity of internal and external issues that can have an effect on an organisation's approach
  • CA combination of internal and external issues that can have an effect on an organisation's
  • DThe coordination of internal and external issues that can have a positive or negative effect on an

How the community answered

(47 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    89% (42)
  • D
    2% (1)

Explanation

The context of the organisation is the business environment in which the organisation operates and defines its information security management system (ISMS). It includes the internal and external factors and conditions that can influence the organisation's information security objectives, strategies, and policies. The context of the organisation helps the organisation to identify the scope, boundaries, and requirements of the ISMS, as well as the interested parties and their expectations. The context of the organisation is determined by considering both internal and external issues, such as the organisational structure, culture, values, mission, vision, objectives, strategies, resources, capabilities, processes, activities, products, services, markets, customers, competitors, suppliers, partners, regulators, laws, regulations, standards, guidelines, best practices, risks, opportunities, threats, vulnerabilities, etc.

Topics

#context of organization#ISO 27001 clause 4#internal external issues

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice