IT Governance – An international guide to data security and ISO 27001/ISO 27002, Eighth edition
by Alan Calder, Steve Watkins
CHAPTER 25: COMPLIANCE
Clause 4.2 of ISO 27001 requires organizations to “understand the needs and expectations of interested parties” and, to that end, to determine their relevant requirements. The note to this clause recognizes that these requirements can include legal and regulatory requirements and contractual obligations.
Laws are made by legislative bodies, such as the European Parliament, the UK Parliament, the US Congress, or US state congresses. The Data Protection Act, in the UK, is a law. Regulations are requirements typically issued by executive bodies, under powers delegated to them by legislative bodies. The FRC requirements that apply to financial-sector entities in the UK are examples of regulations. Contractual obligations exist ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access