Home / Rules / ISO/IEC 27001:2022 / ISO/IEC 27001:2022 Annex A 5.21 Managing information security in the ICT supply chain
ISO/IEC 27001:2022 Annex A 5.21 Managing information security in the ICT supply chain
Processes and procedures are to be defined and put in place to manage information security risks in the supply chain for ICT products and services. Purpose (stated in ISO/IEC 27002:2022): keeps security across the ICT product and service supply chain at the agreed level.
Steps that cite it
- KC-01 S5 Assess the vendor's assurance report
Evidence commonly asked for
- Statement of Applicability entry for control A.5.21, showing inclusion or justified exclusion, implementation status and the risks it treats
- Security requirements included in ICT acquisition specifications and contracts, including flow-down to sub-suppliers
- Software component information such as SBOMs and descriptions of security functions and secure configuration obtained from product suppliers
- A list of critical ICT components with provenance and traceability evidence
Accepted citation forms are listed on the answer format page.