5.20 Addressing information security within supplier agreements
Requires the relevant information security requirements to be established and agreed with each supplier, scaled to the type of supplier relationship involved.
5
artefacts
0
held by a system
0
at each review
hard
to go live
Vendor register / contract repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Executed agreements containing the agreed information security requirements, sampled across supplier tiers · Vendor register / contract repository
- The clause set used, covering confidentiality, information handling, incident notification with a timeframe, subcontracting, personnel screening, return or deletion at exit and right to audit · HR system / LMS
- Evidence requirements were scaled to the relationship type rather than applied as one template regardless · Vendor register / contract repository
- Records of negotiation outcomes where a supplier refused a clause, and the risk acceptance behind that · Vendor register / contract repository
- Evidence that agreements are revisited when the service or the risk changes · Vendor register / contract repository
First move
This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.
Common gaps auditors find
- Security schedule attached to new contracts only, leaving the long standing critical suppliers on legacy terms with nothing in them
- Incident notification required with no timeframe, so late notification breaches nothing
- Subcontracting unaddressed, so a fourth party handles the information under no equivalent obligation
- Right to audit written in and never exercised, and in practice unexercisable
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet5.19 Information security in supplier relationships · 5.21 Managing information security in the ICT supply chain