ISO/IEC 27001:2022
Attaches to every supplier relationship through controls 5.19 to 5.23, and to outsourced development through 8.30. With no regime ticked, these rows render as the default.
On the register, tick "ISO/IEC 27001 certified" and these rows appear on every vendor the regime reaches. Framework page.
Which vendors it reaches
| Families | Cloud and hosting, Software and SaaS, Network and connectivity, Hardware and devices, Managed and professional services, Data and content, Payments and financial, Operations |
|---|---|
| On every vendor | ISO 27001 5.19, ISO 27001 5.20, ISO 27001 5.22 |
| Cloud and hosting | ISO 27001 5.23, ISO 27001 5.21 |
| Software and SaaS | ISO 27001 5.23, ISO 27001 5.21 |
| Network and connectivity | ISO 27001 5.21 |
| Hardware and devices | ISO 27001 5.21 |
| Managed and professional services | ISO 27001 5.21 |
| Data and content | the clauses on every vendor only |
| Payments and financial | the clauses on every vendor only |
| Operations | the clauses on every vendor only |
| Outsourced software development | ISO 27001 8.30 |
ISO/IEC 27001:2022 controls 5.19 to 5.23, supplier agreements
The clauses the register expects in every vendor agreement the regime reaches, and the further clauses for a vendor rated critical.
- The information security requirements agreed for the relationship, in the contract (5.20)
- Incident reporting to the organisation, with a timeframe (5.20)
- Monitoring and review rights over the supplier's service delivery (5.22)
- Termination provisions, including the return or destruction of information (5.20)
For cloud and hosting vendors
- Exit and data migration procedures for the cloud service (5.23)
- Security requirements flowed down the ICT supply chain (5.21)
For software and saas vendors
- Exit and data migration procedures for the cloud service (5.23)
- Security requirements flowed down the ICT supply chain (5.21)
For network and connectivity vendors
- Security requirements flowed down the ICT supply chain (5.21)
For hardware and devices vendors
- Security requirements flowed down the ICT supply chain (5.21)
For managed and professional services vendors
- Security requirements flowed down the ICT supply chain (5.21)
The clauses, quoted
6 of 93 in the frameworkRequirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO 27001 5.19 Information security in supplier relationshipsDefine and apply processes to manage the security risk suppliers introduce.
Common gap: Treating all suppliers as low risk
Source framework: ISO/IEC 27001:2022
ISO 27001 5.20 Addressing information security within supplier agreementsEstablish and agree the relevant security requirements in each supplier contract.
Common gap: missing explicit security clauses
Source framework: ISO/IEC 27001:2022
ISO 27001 5.22 Monitoring, review and change management of supplier servicesRegularly monitor, review and manage change in supplier security practice and service delivery.
Common gap: relying on informal verbal updates
Source framework: ISO/IEC 27001:2022
ISO 27001 5.23 Information security for use of cloud servicesGovern acquisition, use, management and exit of cloud services against your security requirements.
Common gap: Relying solely on provider's security assurances
Source framework: ISO/IEC 27001:2022
ISO 27001 5.21 Managing information security in the ICT supply chainExtend security requirements down the ICT products and services supply chain.
Common gap: Treating supplier security as one-off check
Source framework: ISO/IEC 27001:2022
ISO 27001 8.30 Outsourced developmentDirect, monitor and review outsourced system development.
Common gap: contracts lack specific security obligations
Source framework: ISO/IEC 27001:2022
See what it attaches to your list
Paste the vendor list, tick the regime, and every vendor it reaches carries these rows. Eight vendors free, no account.
Build my vendor register