Skip to main content
Category: ISMS Clauses and Planning

Internal and External Issues

Also known as: Context of the Organization Issues, Internal and External Factors
Simply put

Internal and external issues are the factors inside and outside an organization that can affect its ability to achieve its intended objectives, including matters like company culture, staffing, resources, and operational risks internally, and factors such as economic conditions, legislation, and competitors externally. Under a management system standard, an organization is expected to identify these issues as part of understanding its own context. This understanding then informs how the management system is designed and how risks and opportunities are addressed.

Formal definition

In the context of ISO management system standards, internal and external issues are the relevant factors identified when establishing the context of the organization. Internal issues typically include organizational structure, culture, employee competence, process efficiency, resources, and operational risks, while external issues typically include economic conditions, new legislation, competitive pressures, and other market or environmental factors. Identifying these issues is a foundational step that feeds into the determination of risks and opportunities and, within an ISMS, informs the scope and risk assessment. The specific issues considered depend on the organization and are determined during scoping rather than being fixed by a universal list.

Why it matters

Identifying internal and external issues is the foundation on which an effective ISMS is built. Under ISO/IEC 27001, understanding the context of the organization comes first because it shapes almost everything that follows: the scope of the management system, the risks and opportunities the organization chooses to address, and the design of controls that respond to those risks. An ISMS built without a clear grasp of the organization's culture, resources, competence, legislative environment, and competitive pressures risks being generic and disconnected from the realities it is meant to protect against.

For organizations pursuing certification, this step is also where auditors from an accredited certification body often probe deeply. A Statement of Applicability and risk assessment that do not trace back to a considered understanding of internal and external issues can appear arbitrary, and certification bodies typically expect to see that the identified issues genuinely informed the ISMS design rather than being a box-ticking exercise. Because the specific issues depend on the organization and are determined during scoping, there is no universal checklist to fall back on; the quality of this analysis varies considerably between organizations.

It is worth noting the limitations of this concept. Identifying internal and external issues does not by itself guarantee that risks are well managed, and it does not extend beyond the defined scope of the ISMS. It is an input to risk assessment, not a substitute for it. Organizations should treat the analysis as a living reference that is revisited as conditions change rather than a one-time document produced only for the initial certification.

Who it's relevant to

ISMS Managers and Implementers
Those responsible for building or maintaining an ISMS use the identification of internal and external issues as the starting point for defining scope and for feeding the determination of risks and opportunities. A well-documented analysis makes downstream decisions, such as risk treatment and control selection, easier to justify.
Certification Auditors
Auditors from an accredited certification body typically review whether identified issues genuinely informed the ISMS design, including its scope and risk assessment. They tend to look for a traceable connection between context, risk, and the Statement of Applicability rather than a standalone document.
GRC and Compliance Professionals
Governance, risk, and compliance teams rely on a clear understanding of internal and external factors, such as staffing, resources, legislation, and competitive conditions, to keep the ISMS aligned with the organization's actual operating environment as circumstances change over time.
Senior Leadership
Because internal issues such as culture, structure, and resources are shaped at the top of the organization, leadership involvement helps ensure the identified issues reflect strategic realities and that the ISMS is grounded in an accurate picture of the organization's context.

Inside Internal and External Issues

Clause 4.1 Requirement
The determination of internal and external issues is a requirement of Clause 4.1 of ISO/IEC 27001, which sits within the ISMS requirements (clauses 4 through 10) that form the certifiable portion of the standard. It requires the organization to identify issues relevant to its purpose that affect its ability to achieve the intended outcomes of the information security management system.
External Issues
Factors originating outside the organization that may influence the ISMS. Depending on context, these can include the legal, regulatory, technological, competitive, market, cultural, social, and economic environment, whether international, national, regional, or local. The specific issues identified vary by organization and scope.
Internal Issues
Factors originating inside the organization that may affect the ISMS. Depending on context, these can relate to governance, organizational structure, roles and accountabilities, policies, objectives, resources, knowledge, information systems, and organizational culture. The relevant issues depend on the nature of the organization and its defined ISMS scope.
Relationship to Context of the Organization
Clause 4.1 forms part of the broader 'Context of the Organization' section, which also addresses interested parties and their requirements (typically Clause 4.2) and the determination of the ISMS scope (typically Clause 4.3). The issues identified inform how scope and the management system are defined.
Input to Risk Assessment and Planning
The internal and external issues identified typically serve as an input to the ISMS planning activities, including risk assessment, and help inform which Annex A reference controls are selected via the Statement of Applicability. The connection between issues and downstream planning is expected but its specific form depends on the organization's approach.

Common questions

Answers to the questions practitioners most commonly ask about Internal and External Issues.

Is identifying internal and external issues a SOC 2 requirement or an ISO 27001 requirement?
The concept of formally determining internal and external issues comes from ISO/IEC 27001, where Clause 4.1 requires the organization to identify issues relevant to its purpose that affect its ability to achieve the intended outcomes of the ISMS. SOC 2 does not use this specific terminology. While the Trust Services Criteria include considerations about understanding the entity and its environment as part of the control environment, they are structured differently and should not be treated as identical to Clause 4.1. Satisfying one framework's expectations does not automatically satisfy the other's, since mapping between SOC 2 and ISO 27001 is partial.
Does documenting internal and external issues mean the organization has to implement controls for every issue it identifies?
No. Identifying internal and external issues under Clause 4.1 informs the scope of the ISMS and feeds into risk assessment, but it does not by itself dictate which controls are implemented. In ISO 27001, control selection is driven by the risk assessment and documented through the Statement of Applicability, which references Annex A controls. Issues are contextual inputs that help shape those later decisions rather than a checklist of mandatory controls.
How does an organization typically go about identifying its internal and external issues?
In most engagements, organizations use structured methods to gather this context, such as reviewing the organization's strategic objectives, regulatory and legal landscape, market and competitive conditions, technology dependencies, and internal factors like culture, resources, and governance structures. Some teams use frameworks such as PESTLE or SWOT analysis to organize the analysis, though ISO 27001 does not mandate any particular method. The approach depends on the organization's size, complexity, and scope.
How do internal and external issues relate to defining the scope of the ISMS?
The issues identified under Clause 4.1, together with the needs and expectations of interested parties under Clause 4.2, are inputs used to determine the boundaries and applicability of the ISMS in Clause 4.3. In practice, understanding what internal and external factors are relevant helps the organization decide what to include or exclude from its ISMS scope. Because the certificate covers only the defined scope, this contextual work directly influences what the eventual certification does and does not address.
How often should internal and external issues be reviewed?
ISO 27001 does not specify a fixed frequency, but the standard's emphasis on continual improvement and the requirement to keep the ISMS current mean issues are typically revisited periodically and when significant changes occur. Many organizations review them as part of the management review process and update them when there are notable shifts in the business, regulatory environment, or technology landscape. The appropriate cadence depends on how dynamic the organization's context is.
What kind of documentation do certification bodies typically expect for internal and external issues?
ISO 27001 requires that the organization determine relevant issues, but it is generally flexible about the format of the documentation. In most engagements, auditors look for evidence that the organization has genuinely considered its context and that this analysis connects logically to scope and risk assessment, rather than for a specific template. A concise register or context analysis that is kept current and clearly linked to downstream ISMS decisions is commonly sufficient, though expectations can vary by certification body and auditor.

Common misconceptions

Internal and external issues are a concept unique to information security or invented by ISO 27001.
The determination of internal and external issues is a common requirement across ISO management system standards that share the harmonized high-level structure. In ISO 27001 it is applied specifically to the information security management system, but the concept itself is not exclusive to this standard.
There is a mandatory, standardized list of internal and external issues an organization must document.
ISO 27001 does not prescribe a fixed list. The relevant issues depend on the organization's purpose, context, and defined ISMS scope, so the issues identified will differ between organizations and, in most engagements, are determined through the organization's own analysis rather than a template.
Identifying internal and external issues is relevant to SOC 2 in the same way it is to ISO 27001.
Clause 4.1 is an ISO/IEC 27001 ISMS requirement and is not a Trust Services Criterion. SOC 2 is an attestation examination performed by a licensed CPA firm against the Trust Services Criteria; while an organization's context may inform a SOC 2 scoping decision, the specific Clause 4.1 requirement belongs to ISO 27001 and should not be conflated with SOC 2 concepts.

Best practices

Document internal and external issues in a way that clearly ties them to the purpose of the organization and the defined scope of the ISMS, since Clause 4.1 issues are expected to be relevant to the management system's intended outcomes.
Consider both categories separately, distinguishing external factors such as legal, regulatory, technological, and market conditions from internal factors such as governance, structure, resources, and culture, to avoid overlooking relevant issues.
Use the identified issues as an input to ISMS planning and risk assessment, and carry the relevant outputs through to control selection reflected in the Statement of Applicability rather than treating the analysis as a standalone exercise.
Review and update the internal and external issues periodically, as context can change over time; the appropriate review frequency depends on the organization and its rate of change.
Align the issues analysis with the identification of interested parties and their requirements and with the determination of ISMS scope, since these context clauses are interrelated.
Specify which version of ISO/IEC 27001 the analysis is based on when referencing clause structure, and be prepared to demonstrate the analysis to the accredited certification body, as it may be examined during certification against the ISMS requirements.