The Requirement
ISO 27001 requires you to identify applicable legal, regulatory, and contractual requirements related to information security (Clause 4.2, A.5.31).
What to Include
Legislation
•Data protection laws (GDPR, UK GDPR, etc.)
•Computer misuse / cybercrime laws
•Industry-specific regulations (financial services, healthcare, etc.)
•Employment law (as it relates to information security)
Regulations
•Sector-specific security standards
•National security requirements (if applicable)
Contractual
•Customer security requirements
•SLA commitments
•NDA obligations
•Insurance requirements
What NOT to Include
•Every law in your jurisdiction
•Laws that don't relate to information security
•Requirements you can't actually influence
Practical Tips
1Start with what you know — GDPR is obvious; add from there
2Ask your legal team — They should know your key obligations
3Check customer contracts — Many contain security clauses
4Review regularly — Laws change; your register should too
5Link to controls — Show how you comply with each requirement
Auditor Expectation
Auditors want to see that you've identified relevant obligations and can demonstrate compliance. They don't expect you to be legal experts — they expect you to know what applies to you and how you address it.