SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

List of Legal, Regulatory, Contractual and Other Requirements

  Quote
Guest
Guest user Created:   May 31, 2019 Last commented:   May 31, 2019

List of Legal, Regulatory, Contractual and Other Requirements

I‘m working with a client in implementing ISO 27001. I was trying to explain to him that they need to have a list of interested parties , legal and contractual requirements but I was wondering if you could send me an example of such a document i.e partially filled out so I can better explain this to him ?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 31, 2019

First it is important to note that you only have to develop such list if control A.18.1.1 (Identification of applicable legislation and contractual requirements) is applicable to your organization (the main clauses of the standard only require that such information must be considered with no need to document it).

Regarding a partially filled document, unfortunately such information is protected by confidentiality agreements with our customers, but here is a practical example of how to fill this template:

Consider that, a customer named Jon has a service level agreement with your company which defines, on clause 32-b, that access to all information provided by the customer to information system ABC are restricted to customer personnel only. In this case the person responsible for system ABC is responsible to ensure compliance of the system to this requirement. Then your document would be like this:

Interested party: Customer Jon
Requirement: Clause 32-b (Information provided to system ABC are restricted to customer's personnel)
Document: Service level agreement
Person responsible for compliance: System ABC administrator
Deadline: when system ABC is made available for customer use

Besides Service Level Agreements, you should consider laws and regulations applicable to the locations where you operate. For identification of specific requirements for your organization we recommend you to seek for expert legal advise.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 31, 2019

May 31, 2019