ISO/IEC 27000 Legal, Statutory, Regulatory and Contractual Requirements, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to legal, statutory, regulatory and contractual requirements.
Assessment Step
1
Legal, Statutory, Regulatory and Contractual Requirements (LegalStatutoryRegulatoryandContractualRequirements)
Has the organization identified and documented all legal, statutory, regulatory, and contractual requirements relevant to information security, and has it identified and documented its approach to meeting those requirements, and does it keep this information up to date?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Legal, Statutory, Regulatory and Contractual Requirements
Legal, statutory, regulatory and contractual requirements relevant to information security and the organization's approach to meet these requirements shall be identified, documented and kept up to date.
Citations
27001
Annex A, Control 5.31
27002
Section 5.31
|