4.2 Understanding the needs and expectations of interested
parties
The organization
shall determine the interested parties that are relevant to the Information
Security Management System and the requirements of these interested parties
that are relevant to the Information Security Management System.
The details of
the interested parties (Internal and external) are maintained as version 1.1
dated xyz
4.3 Determining the scope of the Information
Security Management System
The scope for the information Security management system as applicable
to M/s ABC PVT. LTD. is as follows: software system control including supply chain
4.4 Information Security Management System and its processes.
The risk
assessment shall be done / reviewed on regular basis ( at least once per year)
The action
required to mitigate the risk identified are recorded and maintained.
Other methods
which are used to find out the gaps are the internal and external audits and
management review meeting etc.
User questions & answers