Toolkit content
Assign topic to the user
4.1 Understand organization and context
4.2 understanding the needs and expectations of stakeholders
Please inform where I can find this to be able to implement as required by the standard.)
Answer:
ISO 27001 does not require the documentation of organizational context, only that you consider them to identify needs and expectations of stakeholders.
To cover requirements from section 4.2 you can use the "Procedimiento para identificación de requisitos" and the "Apéndice: Lista de requisitos legales, normativos, contractuales y de otra índole" templates, which are located on folder 2 "02_Procedimiento_para_identificacion_de_requisitos"
These articles will provide you further explanation about organizational context and needs and expectations of stakeholders:
- How to define context of the organization according to ISO 27001 htt ps://advisera.com/27001academy/knowledgebase/how-to-define-context-of-the-organization-according-to-iso-27001/
- How to identify ISMS requirements of interested parties in ISO 27001 https://advisera.com/27001academy/blog/2017/02/06/how-to-identify-isms-requirements-of-interested-parties-in-iso-27001/
Comment as guest or Sign in
Nov 22, 2018