Limited-time offer
Lock in 2024 prices now for ISO 27001 toolkits, course exams, and software!
This offer is valid until December 19, 2024.

Expert Advice Community

Guest

Identifying Legal Requirements

  Quote
Guest
Guest user Created:   Feb 14, 2017 Last commented:   Feb 14, 2017

Identifying Legal Requirements

1 - How do I define the List of Legal Regulatory Contractual and Other Requirements? I read all the articles about it, but I still don't know how to define it. There's also no video tutorial on how to identify these requirements.
0 0

Assign topic to the user

ISO 27001 PROCEDURE FOR IDENTIFICATION OF REQUIREMENTS

Basics of identification of interested parties and their requirements.

ISO 27001 PROCEDURE FOR IDENTIFICATION OF REQUIREMENTS

Basics of identification of interested parties and their requirements.

Expert
Rhand Leal Feb 14, 2017

Answer: The most common ways to gather this kind of information is by interviewing people involved in the process (e.g., operators, technical staff, process owners, contract managers, legal support, etc.), reading the available documentation, and by doing an Internet search. By applying these three methods you will have a good base for which legal, regulatory and other requirements you must comply.

2 - And what if my organization has several locations in different countries?"

Answer: The methods described are still applicable, but you have to ensure to collect this information also from people living in those countries, not only from someone who made an Internet search, because they generally have a closer and better view of what is relevant and needed in terms of requirements.

This article will provide you fu rther explanation about identifying requirements:
- How to identify ISMS requirements of interested parties in ISO 27001 https://advisera.com/27001academy/blog/2017/02/06/how-to-identify-isms-requirements-of-interested-parties-in-iso-27001/

These materials will also help you regarding identification of legal requirements:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 14, 2017

Feb 14, 2017

Suggested Topics

Guest user Created:   Jun 03, 2019 ISO 27001 & 22301
Replies: 1
0 0

Auditing BCP and DRP