ISO/IEC 27001:2022 Clause 4.2 – Understanding the needs and expectations of interested parties states:
“The organization shall determine:
a) interested parties that are relevant to the ISMS;
b) the relevant requirements of these interested parties.”
Risk identification must incorporate input from all relevant stakeholders, including but not limited to experts. In fact, ISO/IEC 27005:2022 emphasizes stakeholder engagement in risk assessments to improve understanding of risk context and ensure comprehensive input.
[References:, ISO/IEC 27001:2022 Clause 4.2, ISO/IEC 27005:2022 Clause 6.3 – Risk identification & stakeholder involvement===========, , , ]
Submit