[{"data":1,"prerenderedAt":317},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"regulation-en-iso-27001":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":52,"entities":267,"extension":270,"faq":271,"keywords":290,"meta":295,"navigation":296,"ogImage":297,"path":51,"persona":298,"publishedAt":297,"regulation":299,"relatedFeatures":300,"relatedPages":303,"seo":306,"shortTitle":50,"slug":299,"sources":307,"stem":313,"tldr":314,"updatedAt":315,"__hash__":316},"regulations_en\u002Fen\u002Fregulations\u002Fiso-27001.md","ISO 27001: Centralised SoA and Annex A Controls | CISAPP","CISAPP",{"type":108,"value":109,"toc":260},"minimark",[110,115,123,146,150,232,241,245,248],[111,112,114],"h2",{"id":113},"what-does-iso-27001-require-on-suppliers","What does ISO 27001 require on suppliers?",[116,117,118,122],"p",{},[119,120,121],"strong",{},"ISO\u002FIEC 27001 is the international information security management standard, and its 2022 version dedicates five controls to supplier relationships."," The requirement does not stop at signature: it covers policy definition, contracting, the ICT supply chain, ongoing monitoring and the specific case of cloud services.",[124,125,126],"key-takeaways",{},[127,128,129,133,136,143],"ul",{},[130,131,132],"li",{},"93 Annex A controls across four themes since the 2022 version.",[130,134,135],{},"Controls A.5.19 to A.5.23 cover the whole supplier lifecycle.",[130,137,138,139,142],{},"The Statement of Applicability must justify every selected control ",[119,140,141],{},"and"," every exclusion.",[130,144,145],{},"A supplier certificate is only worth the scope and duration it states.",[111,147,149],{"id":148},"the-five-supplier-controls-in-annex-a","The five supplier controls in Annex A",[151,152,154],"comparison-table",{"caption":153},"ISO\u002FIEC 27001:2022 controls on suppliers",[155,156,157,173],"table",{},[158,159,160],"thead",{},[161,162,163,167,170],"tr",{},[164,165,166],"th",{},"Control",[164,168,169],{},"Purpose",[164,171,172],{},"Evidence expected at audit",[174,175,176,188,199,210,221],"tbody",{},[161,177,178,182,185],{},[179,180,181],"td",{},"A.5.19",[179,183,184],{},"Information security in supplier relationships",[179,186,187],{},"Approved supplier policy",[161,189,190,193,196],{},[179,191,192],{},"A.5.20",[179,194,195],{},"Security requirements in agreements",[179,197,198],{},"Standard contract clauses and signed contracts",[161,200,201,204,207],{},[179,202,203],{},"A.5.21",[179,205,206],{},"ICT supply chain security",[179,208,209],{},"Dependency analysis, including tier 2",[161,211,212,215,218],{},[179,213,214],{},"A.5.22",[179,216,217],{},"Monitoring and review of supplier services",[179,219,220],{},"Dated reassessments, incident tracking",[161,222,223,226,229],{},[179,224,225],{},"A.5.23",[179,227,228],{},"Security of cloud service use",[179,230,231],{},"Inventory of cloud services and their configurations",[116,233,234,235,240],{},"Control A.5.21 points explicitly at ",[236,237,239],"a",{"href":238},"\u002Fen\u002Fglossary\u002Ffourth-party-risk","fourth-party risk",": the ICT supply chain extends beyond the direct supplier.",[111,242,244],{"id":243},"how-cisapp-keeps-the-soa-and-evidence-current","How CISAPP keeps the SoA and evidence current",[116,246,247],{},"The same framework applies to your organisation and to your third parties. Controls are linked to the evidence supporting them, the SoA updates as assessments come in rather than the night before the audit, and certificates shared by your suppliers are tracked with validity dates and expiry alerts — an expired certificate is no certificate at all to an auditor.",[116,249,250,251,254,255,259],{},"See also the ",[236,252,253],{"href":6},"DORA and ISO 27001 compliance software"," solution and the ",[236,256,258],{"href":257},"\u002Fen\u002Fglossary\u002Fsecurity-questionnaire","security questionnaire"," glossary entry.",{"title":261,"searchDepth":262,"depth":262,"links":263},"",2,[264,265,266],{"id":113,"depth":262,"text":114},{"id":148,"depth":262,"text":149},{"id":243,"depth":262,"text":244},[268,269],"Vendor due diligence","Security questionnaire","md",[272,275,278,281,284,287],{"q":273,"a":274},"What is the ISO 27001 standard?","ISO\u002FIEC 27001 is the international standard defining the requirements for an information security management system (ISMS): context, governance, risk assessment, risk treatment, effectiveness measurement and continual improvement. It is the standard in the 27000 family against which an organisation can be certified.",{"q":276,"a":277},"What does Annex A of the 2022 version contain?","Annex A of the 2022 version has 93 controls across four themes: organisational, people, physical and technological. It reorganises the 114 controls in 14 clauses of the 2013 version without reducing the coverage.",{"q":279,"a":280},"Which ISO 27001 controls cover suppliers?","Controls A.5.19 to A.5.23 address information security in supplier relationships: a dedicated policy, security requirements in agreements, ICT supply chain security, monitoring and review of supplier services, and security of cloud service use.",{"q":282,"a":283},"What is the Statement of Applicability (SoA)?","The SoA is the document listing the controls selected, justifying their selection, stating whether they are implemented and motivating exclusions. It is a central artefact examined during certification audits, and the one that ages fastest when maintained apart from the rest of the ISMS.",{"q":285,"a":286},"Is requiring ISO 27001 from your suppliers enough?","No. A certificate attests that an ISMS was audited over a given scope, at a given date. You need to check the scope covered, the certificate validity and the associated Statement of Applicability, because the service you buy may fall outside the scope.",{"q":288,"a":289},"Does CISAPP generate the Statement of Applicability?","Yes. The ISO 27001 module keeps your SoA current, linked to Annex A controls and their supporting evidence, and centralises supplier certificates with validity dates and expiry alerts.",[50,291,292,293,294],"ISO 27001 SoA","Annex A controls","ISO 27001 audit","supplier ISO 27001 certification",{},true,null,"entreprise","iso-27001",[301,302],"Regulatory frameworks","Certifications",[304,305],"nis2","dora",{"title":105,"description":52},[308],{"label":309,"url":310,"publisher":311,"date":312},"ISO\u002FIEC 27001:2022 — Information security management systems","https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F27001","ISO","2022-10-25","en\u002Fregulations\u002Fiso-27001","ISO\u002FIEC 27001:2022 is the international standard for information security management. The 2022 version has 93 Annex A controls across four themes, five of which cover supplier relationships (A.5.19 to A.5.23). Certification requires a justified Statement of Applicability and up-to-date evidence of effectiveness.","2026-08-16","VlOH8SJJdy_uSN1nnhYkv-cvW49_2-_Mbk8GQvreSA4",1791391138654]