A.5.21 Managing information security in the ICT supply chain
Extend security requirements down the ICT products and services supply chain.
15
artefacts
2
held by a system
5
at each review
hard
to go live
Vendor register / contract repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Service level agreement (SLA) security metrics · Vendor register / contract repository
- Communication log for breach notifications · SIEM / log platform
periodic reviewEvidence produced at each review
- Signed contracts with security clauses · Vendor register / contract repository
- Risk assessment report for critical suppliers · Vendor register / contract repository
- Third-party audit report (e.g., ISO 27001 certification) · Vendor register / contract repository
- Supplier self-assessment questionnaire results · Vendor register / contract repository
- Record of past supply-chain security incidents · Document repository
governing documentDocuments that govern the control
- Supplier security requirement specification · Vendor register / contract repository
- Approved supplier security questionnaire · Vendor register / contract repository
- Third-party security policy acknowledgment · HR system / LMS
- Addendum detailing security obligations · Document repository
- Risk register entry for supply chain threats · Policy repository / GRC workspace
- Mitigation plan for identified supplier risks · Vendor register / contract repository
- On-site audit findings report · Vendor register / contract repository
- Joint incident response plan with supplier · Vendor register / contract repository
First move
Mostly documents and reviews. Pull the 2 system-held artefacts from your Vendor register / contract repository on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Treating supplier security as one-off check
- Missing contractual security clauses
- No ongoing monitoring of supplier performance
- Insufficient evidence of incident coordination
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.5.20 Addressing information security within supplier agreements · A.5.22 Monitoring, review and change management of supplier services