nerdexam
PECB

LEAD-AUDITOR · Question #108

Which one of the following options is the definition of the context of an organisation?

The correct answer is C. A combination of internal and external issues that can have an effect on an organisation's. The context of the organisation is the business environment in which the organisation operates and defines its information security management system (ISMS). It includes the internal and external factors and conditions that can influence the organisation's information security ob

Context of the Organization

Question

Which one of the following options is the definition of the context of an organisation?

Options

  • AThe control of internal and external issues that can have an effect on an organisation's desire to
  • BComplexity of internal and external issues that can have an effect on an organisation's approach to
  • CA combination of internal and external issues that can have an effect on an organisation's
  • DThe coordination of internal and external issues that can have a positive or negative effect on an

How the community answered

(27 responses)
  • A
    7% (2)
  • C
    89% (24)
  • D
    4% (1)

Explanation

The context of the organisation is the business environment in which the organisation operates and defines its information security management system (ISMS). It includes the internal and external factors and conditions that can influence the organisation's information security objectives, strategies, and policies. The context of the organisation helps the organisation to identify the scope, boundaries, and requirements of the ISMS, as well as the interested parties and their expectations. The context of the organisation is determined by considering both internal and external issues, such as the organisational structure, culture, values, mission, vision, objectives, strategies, resources, capabilities, processes, activities, products, services, markets, customers, competitors, suppliers, partners, regulators, laws, regulations, standards, guidelines, best practices, risks, opportunities, threats, vulnerabilities, etc.

Topics

#organizational context#ISO 27001 clause 4#internal external issues#ISMS scope

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice