iso27diy-corp/Corpus/Standards/ISO-27001-OST/ISO27001-EN-2022/c-4.2-Understanding-the-needs-and-expectations-of-interested-parties.md

494 B

#iso27001/2022/EN

4.2 Understanding the needs and expectations of interested parties

The organization shall determine:

a) interested parties that are relevant to the information security management system;

b) the relevant requirements of these interested parties;

c) which of these requirements will be addressed through the information security management system.

NOTE The requirements of interested parties can include legal and regulatory requirements and contractual obligations.