FORM AWT-1 · AGENT CHECK SHEET · LIBRARY 1.0SCORER 1.0.0 · 8 PUBLIC SCENARIOS · SPECIMEN DATA
AI Agent Compliance Workflow Tester

Home / Rules / ISO/IEC 27001:2022 / ISO/IEC 27001:2022 Annex A 5.21 Managing information security in the ICT supply chain

ISO/IEC 27001:2022 Annex A 5.21 Managing information security in the ICT supply chain

Processes and procedures are to be defined and put in place to manage information security risks in the supply chain for ICT products and services. Purpose (stated in ISO/IEC 27002:2022): keeps security across the ICT product and service supply chain at the agreed level.

ISO/IEC 27001:2022. Edition: ISO/IEC 27001:2022 (third edition, October 2022) with Amendment 1:2024. Checked 2026-10-07. Our statement of the clause, cited; the standard is licensed and not quoted. Official source. The framework on compliance.theartofservice.com.

Steps that cite it

Evidence commonly asked for

Accepted citation forms are listed on the answer format page.