ISO/IEC 27003:2017 ISO27003-4.2: Understanding the needs and expectations of interested parties
The organization identifies which interested parties matter to the ISMS and what each of them requires in respect of information security. Explanation: an interested party is anyone, person or organization, who can affect the organization's decisions or activities, be affected by them, or believe it is affected (27000:2016, 2.41); such parties sit both outside and inside and may expect or demand particular things of the organization's security. Outside parties can include regulators and legislators; shareholders such as owners and investors; suppliers, among them subcontractors, consultants and outsourcers; industry associations; competitors; customers and consumers; and activist groups. Inside parties can include decision makers including top management; owners of processes, systems and information; IT, human resources and other support functions; employees and users; and information security professionals. The output feeds 4.3 and 6.1. Steps: name the outside parties, name the inside parties, and establish what each requires; because needs and requirements move over time, review their changes and the effect on the ISMS scope, constraints and requirements at regular intervals. Documenting this is required only as far as the organization judges necessary.
This control maps to 113 controls across 66 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition