ISO/IEC 27003:2017
Context of the organization – ISO/IEC 27003:2017

ISO/IEC 27003:2017 ISO27003-4.2: Understanding the needs and expectations of interested parties

The organization identifies which interested parties matter to the ISMS and what each of them requires in respect of information security. Explanation: an interested party is anyone, person or organization, who can affect the organization's decisions or activities, be affected by them, or believe it is affected (27000:2016, 2.41); such parties sit both outside and inside and may expect or demand particular things of the organization's security. Outside parties can include regulators and legislators; shareholders such as owners and investors; suppliers, among them subcontractors, consultants and outsourcers; industry associations; competitors; customers and consumers; and activist groups. Inside parties can include decision makers including top management; owners of processes, systems and information; IT, human resources and other support functions; employees and users; and information security professionals. The output feeds 4.3 and 6.1. Steps: name the outside parties, name the inside parties, and establish what each requires; because needs and requirements move over time, review their changes and the effect on the ISMS scope, constraints and requirements at regular intervals. Documenting this is required only as far as the organization judges necessary.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 113 controls across 66 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • P2-S1 Partnership

IEC 62443 · 3 controls

  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-22 Configuration management for OT systems
  • IEC62443-23 Change management procedures
  • ISO-20400-7.3 Supplier selection
  • ISO-20400-7.4 Contract management and review
  • ISO-20400-7.5 Reviewing and learning

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-22 Configuration management for OT systems
  • ISO27019-23 Change management procedures
  • ISO27019-24 Vulnerability assessment for critical systems
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

NIST SP 1800-32 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

  • RMI-DD-3 Red Flag Review
  • RMI-MS-2 Cobalt Standard
  • RMI-RMAP-2 Risk-Based Audit Approach

Solvency II · 3 controls

  • SII-P2-09 Outsourcing Requirements
  • SII-P2-12 Written Policies
  • SII-P3-06 SFCR Section B: System of Governance
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • A.1 Point-of-Care Testing Additional Requirements
  • ISO-15189-6.8 Externally provided products and services
  • ISO28001-PC-03 Supply Chain Incident Reporting
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO-50001-8.3 Procurement
  • 4.2 Understanding the needs and expectations of interested parties

SASB Standards · 2 controls

  • SASB-1 Business Model + Innovation (BMI)
  • SASB-BMI-3 Supply Chain Management
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • Clause 3 Suppliers and service providers
  • ACQ.4 Supplier Monitoring
  • Mat 03 Responsible Sourcing of Materials
  • CJIS-19 Supply Chain Risk Management
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

ISO 14001:2015 · 1 control

  • 4.2 Understanding the needs and expectations of interested parties

ISO 14004:2016 · 1 control

  • 4.2 Understanding the needs and expectations of interested parties

ISO 22000:2018 · 1 control

  • 4.2 Understanding the needs and expectations of interested parties

ISO 22301:2019 · 1 control

  • 4.2 Understanding the needs and expectations of interested parties

ISO 22316 · 1 control

  • ISO22316-14 Supply chain continuity

ISO 26000:2010 · 1 control

  • ISO-26000-6.6 Fair operating practices

ISO 27701:2019 · 1 control

  • 5.2.2 Understanding the needs and expectations of interested parties

ISO 37301:2021 · 1 control

  • 4.2 Understanding the needs and expectations of interested parties
  • ISO-41001-8.4 Control of outsourced processes and services

ISO 45001:2018 · 1 control

  • 4.2 Understanding the needs and expectations of workers and other interested parties

ISO 9001:2015 · 1 control

  • 4.2 Understanding the needs and expectations of interested parties

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.6 AI System Security

ISO/IEC 27010:2015 · 1 control

  • 27010-15.1 Incident Management

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

ISO/IEC 42001:2023 · 1 control

  • 4.2 Understanding the needs and expectations of interested parties

ISO/TS 22317:2021 · 1 control

  • ISO22317-14 Supply chain continuity

ISO/TS 22318:2021 · 1 control

  • ISO22318-14 Supply chain continuity

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • OWASPLLM-4 Supply Chain and Vector/Embedding Weaknesses (LLM03 + LLM08)
  • PASONE-3 Personnel Security, Vetting, Awareness, and Training
  • PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management
  • PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets
  • SAEIGHT-7 Management System, Worker Engagement, Continuous Improvement
  • 2.7.2 Food Fraud Plan
  • SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain
  • IM8-TPM.4 Supply Chain Risk Management

South Korea ISMS-P · 1 control

  • ISMSP-PI-03 Third-Party Provision and Outsourcing
  • UKOPRES-5 Third-Party Risk, Concentration Risk
  • UKGAMBLE-4 Resilience and Incident Response
  • UK-TSA-NET-03 Supply Chain Security

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Context of the organization – ISO/IEC 27003:2017

Query this from an agent

The graph holds this control, the 113 it maps to, and the evidence behind each claim, over MCP and REST.