All data is fictional

Interested Parties

ISO 27001:2022 Clause 4.2 — Stakeholder needs & expectations

All Interested Parties (12)
NameCategoryTypeCIA ImpactKey RequirementsOwnerReview FrequencyStatus
Enterprise CustomersClientExternalCIASOC 2, SLA uptime, data privacyCCOAnnualActive
Information Commissioner's OfficeRegulatorExternalCIGDPR compliance, breach notificationDPOAnnualActive
AWS (Cloud Provider)SupplierExternalCIAShared responsibility model, SCC DPACTOAnnualActive
EmployeesWorkforceInternalCASafe working environment, data privacyHR DirectorAnnualActive
Shareholders / BoardGovernanceInternalCIFinancial data integrity, risk postureCEOQuarterlyActive
Cyber Insurance ProviderInsurerExternalCIASecurity posture, incident disclosureCFOAnnualActive
Auditors (External)AuditorExternalCIAudit evidence, documentation accessCISOAnnualActive
NCSC (UK)RegulatorExternalCIACyber Essentials, NIS 2 reportingCISOAnnualActive
Sub-processors (3rd party SaaS)SupplierExternalCIDPA in place, security questionnaireDPOAnnualActive
Prospective CustomersClientExternalCSecurity questionnaires, certificationsCCOAd hocActive
Engineering TeamWorkforceInternalIASecure SDLC, patching SLAsCTOBi-annualActive
Pen Testing PartnerSupplierExternalCINDA, scoped rules of engagementCISOAnnualActive