ISO/IEC 27001:2022
Rendered when the buyer ticks "ISO/IEC 27001 certified". The register cites 6 of its 93 clauses, behind 8 findings: single-source vendors with no fallback named, concentration at or above the threshold, hardware with an unconfirmed country of origin, contracts ending inside 90 days with no re-tender noted, critical vendors with no contract end recorded, nis2 supplier assessment not evidenced, cloud services with no exit plan, sub-outsourcing chains longer than one hop, and on the obligation rows of every vendor it reaches.
Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Framework page. What it attaches to a vendor: the ISO 27001 regime page.
Clauses cited
6 of 93ISO 27001 5.19 Information security in supplier relationshipsDefine and apply processes to manage the security risk suppliers introduce.
Common gap: Treating all suppliers as low risk
Source framework: ISO/IEC 27001:2022
ISO 27001 5.22 Monitoring, review and change management of supplier servicesRegularly monitor, review and manage change in supplier security practice and service delivery.
Common gap: relying on informal verbal updates
Source framework: ISO/IEC 27001:2022
ISO 27001 5.21 Managing information security in the ICT supply chainExtend security requirements down the ICT products and services supply chain.
Common gap: Treating supplier security as one-off check
Source framework: ISO/IEC 27001:2022
ISO 27001 5.20 Addressing information security within supplier agreementsEstablish and agree the relevant security requirements in each supplier contract.
Common gap: missing explicit security clauses
Source framework: ISO/IEC 27001:2022
ISO 27001 5.23 Information security for use of cloud servicesGovern acquisition, use, management and exit of cloud services against your security requirements.
Common gap: Relying solely on provider's security assurances
Source framework: ISO/IEC 27001:2022
ISO 27001 8.30 Outsourced developmentDirect, monitor and review outsourced system development.
Common gap: contracts lack specific security obligations
Source framework: ISO/IEC 27001:2022
See which clauses your list engages
Paste the list and every vendor names the clauses behind it, filtered to the regimes that apply to you. Eight vendors free, no account.
Build my vendor register