LEAD-AUDITOR · Question #71
Which one of the following options is the definition of an interested party?
The correct answer is B. A person or organisation that can affect, be affected by or perceive itself to be affected by a. This is the definition of an interested party according to ISO 27001:2013, clause 3.16. An interested party is essentially a stakeholder, i.e., a person or organization that can influence or be influenced by the information security management system (ISMS) or its activities. Int
Question
Which one of the following options is the definition of an interested party?
Options
- AA third party can appeal to an organisation when it perceives itself to be affected by a decision or
- BA person or organisation that can affect, be affected by or perceive itself to be affected by a
- CA group or organisation that can interfere in or perceive itself to be interfered with by a
- DAn individual or organisation that can control, be controlled by, or perceive itself to be controlled by
How the community answered
(19 responses)- B89% (17)
- C5% (1)
- D5% (1)
Explanation
This is the definition of an interested party according to ISO 27001:2013, clause 3.16. An interested party is essentially a stakeholder, i.e., a person or organization that can influence or be influenced by the information security management system (ISMS) or its activities. Interested parties can have different needs and expectations regarding the ISMS, and these should be identified and addressed by the organization.
Topics
Community Discussion
No community discussion yet for this question.