Vendor Register
Regimes ยท ISO 27001

ISO/IEC 27001:2022

Attaches to every supplier relationship through controls 5.19 to 5.23, and to outsourced development through 8.30. With no regime ticked, these rows render as the default.

On the register, tick "ISO/IEC 27001 certified" and these rows appear on every vendor the regime reaches. Framework page.

Which vendors it reaches

FamiliesCloud and hosting, Software and SaaS, Network and connectivity, Hardware and devices, Managed and professional services, Data and content, Payments and financial, Operations
On every vendorISO 27001 5.19, ISO 27001 5.20, ISO 27001 5.22
Cloud and hostingISO 27001 5.23, ISO 27001 5.21
Software and SaaSISO 27001 5.23, ISO 27001 5.21
Network and connectivityISO 27001 5.21
Hardware and devicesISO 27001 5.21
Managed and professional servicesISO 27001 5.21
Data and contentthe clauses on every vendor only
Payments and financialthe clauses on every vendor only
Operationsthe clauses on every vendor only
Outsourced software developmentISO 27001 8.30

ISO/IEC 27001:2022 controls 5.19 to 5.23, supplier agreements

The clauses the register expects in every vendor agreement the regime reaches, and the further clauses for a vendor rated critical.

  1. The information security requirements agreed for the relationship, in the contract (5.20)
  2. Incident reporting to the organisation, with a timeframe (5.20)
  3. Monitoring and review rights over the supplier's service delivery (5.22)
  4. Termination provisions, including the return or destruction of information (5.20)

For cloud and hosting vendors

  1. Exit and data migration procedures for the cloud service (5.23)
  2. Security requirements flowed down the ICT supply chain (5.21)

For software and saas vendors

  1. Exit and data migration procedures for the cloud service (5.23)
  2. Security requirements flowed down the ICT supply chain (5.21)

For network and connectivity vendors

  1. Security requirements flowed down the ICT supply chain (5.21)

For hardware and devices vendors

  1. Security requirements flowed down the ICT supply chain (5.21)

For managed and professional services vendors

  1. Security requirements flowed down the ICT supply chain (5.21)

The clauses, quoted

6 of 93 in the framework

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO 27001 5.19 Information security in supplier relationships

Define and apply processes to manage the security risk suppliers introduce.

Evidence an auditor accepts: supplier_risk_assessment; contractual_security_requirements; supplier_security_monitoring
Common gap: Treating all suppliers as low risk
Source framework: ISO/IEC 27001:2022
ISO 27001 5.20 Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

Evidence an auditor accepts: contract_security_clauses; supplier_risk_assessment; security_incident_reporting
Common gap: missing explicit security clauses
Source framework: ISO/IEC 27001:2022
ISO 27001 5.22 Monitoring, review and change management of supplier services

Regularly monitor, review and manage change in supplier security practice and service delivery.

Evidence an auditor accepts: supplier_security_monitoring_reports; supplier_service_review_meetings; supplier_change_management_records
Common gap: relying on informal verbal updates
Source framework: ISO/IEC 27001:2022
ISO 27001 5.23 Information security for use of cloud services

Govern acquisition, use, management and exit of cloud services against your security requirements.

Evidence an auditor accepts: cloud_service_selection; cloud_contract_management; cloud_security_monitoring
Common gap: Relying solely on provider's security assurances
Source framework: ISO/IEC 27001:2022
ISO 27001 5.21 Managing information security in the ICT supply chain

Extend security requirements down the ICT products and services supply chain.

Evidence an auditor accepts: supplier_security_requirements; contractual_security_clauses; supply_chain_risk_assessments
Common gap: Treating supplier security as one-off check
Source framework: ISO/IEC 27001:2022
ISO 27001 8.30 Outsourced development

Direct, monitor and review outsourced system development.

Evidence an auditor accepts: outsourced_development_contracts; vendor_security_assessments; development_process_monitoring
Common gap: contracts lack specific security obligations
Source framework: ISO/IEC 27001:2022

See what it attaches to your list

Paste the vendor list, tick the regime, and every vendor it reaches carries these rows. Eight vendors free, no account.

Build my vendor register