EvidenceSheet

5.20 Addressing information security within supplier agreements

Requires the relevant information security requirements to be established and agreed with each supplier, scaled to the type of supplier relationship involved.

5
artefacts
0
held by a system
0
at each review
hard
to go live
Vendor register / contract repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

none for this control

periodic reviewEvidence produced at each review

none for this control

governing documentDocuments that govern the control

  • Executed agreements containing the agreed information security requirements, sampled across supplier tiers · Vendor register / contract repository
  • The clause set used, covering confidentiality, information handling, incident notification with a timeframe, subcontracting, personnel screening, return or deletion at exit and right to audit · HR system / LMS
  • Evidence requirements were scaled to the relationship type rather than applied as one template regardless · Vendor register / contract repository
  • Records of negotiation outcomes where a supplier refused a clause, and the risk acceptance behind that · Vendor register / contract repository
  • Evidence that agreements are revisited when the service or the risk changes · Vendor register / contract repository

First move

This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

5.19 Information security in supplier relationships · 5.21 Managing information security in the ICT supply chain