ISO/IEC 27003:2017 pdf download.Information technology — Security techniques — Information security management systems — Guidance.
ISO/IEC 27003:2017 provides explanation and guidance on ISO/IEC 27001:2013.
4 Context of the organization
4.1 Understanding the organization and its context
Required activity
The organization determines external and internal issues relevant to its purpose and affecting it ability to achieve the intended outcome()of the information security management system(SMS).
As an integral function of the ISMS, the organization continually analyses itself and the world surrounding it. This analysis is concerned with external and internal issues that in some way affect nformation security and how information security can be managed, and that are relevant to the organization’s objectives.
4. 2 Understanding the needs and expectations of interested parties
Required activity
The organization determines interested parties relevant to the ISMS and their requirements relevant to information security.
Interested party is a defined term (see ISO/IEC 27000: 2016, 2. 41 )that refers to persons or organizations that can affect,be affected by, or perceive themselves to be affected by a decision or activity of the organization. Interested parties can be found both outside and inside the organization and can have specific needs, expectations and requirements for the organizations information security.

