Home / Rules / ISO/IEC 27001:2022 / ISO/IEC 27001:2022 Annex A 5.19 Information security in supplier relationships
ISO/IEC 27001:2022 Annex A 5.19 Information security in supplier relationships
The organization is to define and run processes and procedures that manage the information security risks arising from using suppliers' products or services. Purpose (stated in ISO/IEC 27002:2022): keeps security in supplier dealings at the level agreed with the supplier.
Steps that cite it
- KC-01 S2 Set the supplier tier
- KC-01 S5 Assess the vendor's assurance report
- KC-01 S8 Decide the onboarding outcome
Evidence commonly asked for
- Statement of Applicability entry for control A.5.19, showing inclusion or justified exclusion, implementation status and the risks it treats
- The topic-specific supplier relationship policy and its communication record
- A supplier inventory categorized by type and by the information, services and infrastructure each can access
- Supplier due diligence and selection records such as questionnaires, certifications, references and on-site assessment reports, scaled to sensitivity
Accepted citation forms are listed on the answer format page.