Regulations
ISO 27001: Centralised SoA and Annex A Controls
Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.
TL;DR
ISO/IEC 27001:2022 is the international standard for information security management. The 2022 version has 93 Annex A controls across four themes, five of which cover supplier relationships (A.5.19 to A.5.23). Certification requires a justified Statement of Applicability and up-to-date evidence of effectiveness.
What does ISO 27001 require on suppliers?
ISO/IEC 27001 is the international information security management standard, and its 2022 version dedicates five controls to supplier relationships. The requirement does not stop at signature: it covers policy definition, contracting, the ICT supply chain, ongoing monitoring and the specific case of cloud services.
The five supplier controls in Annex A
| Control | Purpose | Evidence expected at audit |
|---|---|---|
| A.5.19 | Information security in supplier relationships | Approved supplier policy |
| A.5.20 | Security requirements in agreements | Standard contract clauses and signed contracts |
| A.5.21 | ICT supply chain security | Dependency analysis, including tier 2 |
| A.5.22 | Monitoring and review of supplier services | Dated reassessments, incident tracking |
| A.5.23 | Security of cloud service use | Inventory of cloud services and their configurations |
Control A.5.21 points explicitly at fourth-party risk: the ICT supply chain extends beyond the direct supplier.
How CISAPP keeps the SoA and evidence current
The same framework applies to your organisation and to your third parties. Controls are linked to the evidence supporting them, the SoA updates as assessments come in rather than the night before the audit, and certificates shared by your suppliers are tracked with validity dates and expiry alerts — an expired certificate is no certificate at all to an auditor.
See also the DORA and ISO 27001 compliance software solution and the security questionnaire glossary entry.
FAQ
ISO/IEC 27001 is the international standard defining the requirements for an information security management system (ISMS): context, governance, risk assessment, risk treatment, effectiveness measurement and continual improvement. It is the standard in the 27000 family against which an organisation can be certified.
Sources
- ISO/IEC 27001:2022 — Information security management systems — ISO, 2022-10-25
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours