Skip to content
arrow_back
search
Annex A 5.31 verified ISO/IEC 27001:2022

Compliance with Information Security Legal Requirements

Identify and stay updated on information security legal obligations to avoid breaches.

record_voice_over

Plain language

This control ensures your organisation knows and keeps updated with all the legal rules about information security. If you miss these rules, your business might face fines or other legal issues, which could harm your reputation and finances.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Legal, statutory, regulatory and contractual requirements relevant to information security and the organization's approach to meet these requirements shall be identified, documented and kept up to date.
verified ISO/IEC 27001:2022 Annex A 5.31
priority_high

Why it matters

Failure to track legal requirements could lead to significant fines, litigation risks, and damage to the organisation's reputation.

settings

Operational notes

Maintain a legal/regulatory obligations register; review quarterly with legal counsel and security, record changes, owners and evidence of compliance actions.

Mapping detail

Mapping

Direction

Controls