This is the definition of an interested party according to ISO 27001:2013, clause 3.16. An interested party is essentially a stakeholder, i.e., a person or organization that can influence or be influenced by the information security management system (ISMS) or its activities. Interested parties can have different needs and expectations regarding the ISMS, and these should be identified and addressed by the organization. References:
ISO/IEC 27001:2013, Information technology — Security techniques — Information security management systems — Requirements, clause 3.16
PECB Candidate Handbook ISO 27001 Lead Auditor, page 10
Identifying interested parties and their expectations for an ISO 27001 ISMS
Examples of ISO 27001 interested parties
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit