Regulations

ISO 27001: Centralised SoA and Annex A Controls

Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.

TL;DR

ISO/IEC 27001:2022 is the international standard for information security management. The 2022 version has 93 Annex A controls across four themes, five of which cover supplier relationships (A.5.19 to A.5.23). Certification requires a justified Statement of Applicability and up-to-date evidence of effectiveness.

What does ISO 27001 require on suppliers?

ISO/IEC 27001 is the international information security management standard, and its 2022 version dedicates five controls to supplier relationships. The requirement does not stop at signature: it covers policy definition, contracting, the ICT supply chain, ongoing monitoring and the specific case of cloud services.

The five supplier controls in Annex A

ISO/IEC 27001:2022 controls on suppliers
ControlPurposeEvidence expected at audit
A.5.19Information security in supplier relationshipsApproved supplier policy
A.5.20Security requirements in agreementsStandard contract clauses and signed contracts
A.5.21ICT supply chain securityDependency analysis, including tier 2
A.5.22Monitoring and review of supplier servicesDated reassessments, incident tracking
A.5.23Security of cloud service useInventory of cloud services and their configurations

Control A.5.21 points explicitly at fourth-party risk: the ICT supply chain extends beyond the direct supplier.

How CISAPP keeps the SoA and evidence current

The same framework applies to your organisation and to your third parties. Controls are linked to the evidence supporting them, the SoA updates as assessments come in rather than the night before the audit, and certificates shared by your suppliers are tracked with validity dates and expiry alerts — an expired certificate is no certificate at all to an auditor.

See also the DORA and ISO 27001 compliance software solution and the security questionnaire glossary entry.

FAQ

ISO/IEC 27001 is the international standard defining the requirements for an information security management system (ISMS): context, governance, risk assessment, risk treatment, effectiveness measurement and continual improvement. It is the standard in the 27000 family against which an organisation can be certified.

Sources

  1. ISO/IEC 27001:2022 — Information security management systems — ISO, 2022-10-25

Ready for the regulations that apply to you

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account