5.21 Managing information security in the ICT supply chain
Requires processes and procedures to be defined and implemented to manage information security risk arising along the supply chain for ICT products and services.
5
artefacts
1
held by a system
0
at each review
hard
to go live
Vendor register / contract repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Records of monitoring for supply chain compromise affecting products in use, and the response taken · SIEM / log platform
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- The process for managing ICT supply chain risk, distinct from general supplier management · Vendor register / contract repository
- Requirements imposed on ICT suppliers regarding their own suppliers, component provenance and secure development · Policy repository / GRC workspace
- Evidence of verification, such as a software bill of materials, component listings or attestation of development practice · Vendor register / contract repository
- Criteria for accepting or rejecting a product or component on supply chain grounds · Document repository
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Supply chain risk assessed at the vendor level with no visibility of the components inside the product
- No software bill of materials requested, so exposure to a compromised library cannot be answered when it matters
- Requirements flowed to the direct supplier only, with no obligation to pass them down
- Hardware provenance, firmware and refurbished equipment not considered at all
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet5.20 Addressing information security within supplier agreements · 5.22 Monitoring, review and change management of supplier services