EvidenceSheet

5.21 Managing information security in the ICT supply chain

Requires processes and procedures to be defined and implemented to manage information security risk arising along the supply chain for ICT products and services.

5
artefacts
1
held by a system
0
at each review
hard
to go live
Vendor register / contract repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Records of monitoring for supply chain compromise affecting products in use, and the response taken · SIEM / log platform

periodic reviewEvidence produced at each review

none for this control

governing documentDocuments that govern the control

  • The process for managing ICT supply chain risk, distinct from general supplier management · Vendor register / contract repository
  • Requirements imposed on ICT suppliers regarding their own suppliers, component provenance and secure development · Policy repository / GRC workspace
  • Evidence of verification, such as a software bill of materials, component listings or attestation of development practice · Vendor register / contract repository
  • Criteria for accepting or rejecting a product or component on supply chain grounds · Document repository

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

5.20 Addressing information security within supplier agreements · 5.22 Monitoring, review and change management of supplier services