Clause 4.2 Understanding the needs and expectations of interested parties
Clause 4.2 in ISO 27001:2022 (ISO/IEC 27001:2022). All ISO 27001:2022 controls held. Open ISO 27001:2022 on the standards site.
The control as we hold it
Understanding the needs and expectations of interested parties. The organization has to work out which interested parties matter to the ISMS, what those parties require, and which of their requirements the ISMS will deal with. The note says such requirements may include legal, regulatory and contractual obligations. Amendment 1:2024 adds a note that relevant interested parties can have requirements related to climate change (the amendment's wording is held only as quoted in a third-party implementation guide).
Reviewed and closest counterparts in the other frameworks
We hold no cross-framework row for Clause 4.2 yet. The reviewed pairs page lists the released pairs and their coverage.
What an auditor commonly asks for
General guidance for this control area (domain: Clause 4), in our words, not a statement of the standard and not binding on an assessor.
- A register of relevant interested parties such as customers, regulators, staff, suppliers and shareholders, with their information security requirements
- A record of which requirements the ISMS will address and which it will not, with reasons
- Links from legal, regulatory and contractual obligations in the register to the controls or processes that meet them
- Evidence the register is reviewed, for example as a management review input