Stekeholders have an interest in the protection of the organisations' assets.
- Asset owner
- CISO / Information Security Officer
- Control owner
- Customer / client
- Data Protection Officer (DPO)
- Data subject
- Employee / staff
- Identified or identifiable person
- Internal / external auditor
- Regulator / supervisory authority
- Risk owner
- Senior management / Board of Directors
- Supplier / third-party service provider (sub-processor)
- System administrator / IT operations