We've purchased your toolkit and I'm having some issues to fill out the document for List of Legal Regulatory Contractual and Other Requirements. Could you please give me some guidance on it? What I actually need is some explanation about how to fill this out. I've listed the interested parties but I'm confused about the other columns. What exactly should I put on: Requirement, Document stipulating the requirement, Person responsible for compliance andDeadlines?
Since you already have identified the interested parties, now you have to identify the documents in which their requirements can be located (e.g. service level agreements, outsourcing contracts, laws, industry regulations, etc.), and the precise requirements that must be fulfilled (e.g., the clauses).
For example, a customer has a service level agreement with your company which defines, on clause 32-b, that access to all information provided by the customer to information system ABC are restricted to customer personnel only. In this case the person responsible for syste m ABC is the responsible to ensure compliance of the system to this requirement. Then your document would be like this:
Interested party: Customer Jon
Requirement: Clause 32-b (Information provided to system ABC are restricted to customer's personnel)
Document: Service level agreement
Person responsible for compliance: System ABC administrator
Deadline: when system ABC is made available for customer use