Home / Rules / ISO/IEC 27001:2022 / ISO/IEC 27001:2022 Annex A 5.20 Addressing information security within supplier agreements
ISO/IEC 27001:2022 Annex A 5.20 Addressing information security within supplier agreements
The information security requirements that matter for each supplier are to be set and agreed with that supplier, depending on the type of relationship. Purpose (stated in ISO/IEC 27002:2022): makes the agreed security level for each supplier binding through written terms.
Steps that cite it
- KC-01 S4 Find the contract clause gaps
Evidence commonly asked for
- Statement of Applicability entry for control A.5.20, showing inclusion or justified exclusion, implementation status and the risks it treats
- Supplier agreements containing security clauses proportionate to the relationship, such as classification mapping, agreed controls, incident notification, subcontracting, right to audit and termination terms
- A register of contracts, memoranda and information-sharing arrangements with outside parties showing what information each covers and when it was last reviewed
- Minimum security requirement templates per information type and access type used as the basis for individual contracts
Accepted citation forms are listed on the answer format page.