Expert TipLegal & Compliance

Legal Register: What You Actually Need to Track

A pragmatic guide to building your legal register without drowning in legislation you don't understand.

Updated 5 Mar 2026

The Requirement

ISO 27001 requires you to identify applicable legal, regulatory, and contractual requirements related to information security (Clause 4.2, A.5.31).

What to Include

Legislation

Data protection laws (GDPR, UK GDPR, etc.)
Computer misuse / cybercrime laws
Industry-specific regulations (financial services, healthcare, etc.)
Employment law (as it relates to information security)

Regulations

Sector-specific security standards
National security requirements (if applicable)

Contractual

Customer security requirements
SLA commitments
NDA obligations
Insurance requirements

What NOT to Include

Every law in your jurisdiction
Laws that don't relate to information security
Requirements you can't actually influence

Practical Tips

1Start with what you know — GDPR is obvious; add from there
2Ask your legal team — They should know your key obligations
3Check customer contracts — Many contain security clauses
4Review regularly — Laws change; your register should too
5Link to controls — Show how you comply with each requirement

Auditor Expectation

Auditors want to see that you've identified relevant obligations and can demonstrate compliance. They don't expect you to be legal experts — they expect you to know what applies to you and how you address it.

Related Modules

Legal Register
Standard Controls
Documents

Related Controls / Clauses

4.2
A.5.31
A.5.34

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.