Home / Rules / ISO/IEC 27001:2022 / ISO/IEC 27001:2022 Annex A 5.22 Monitoring, review and change management of supplier services
ISO/IEC 27001:2022 Annex A 5.22 Monitoring, review and change management of supplier services
On a regular basis the organization is to monitor, review and evaluate suppliers' security practices and service delivery and to manage changes to them. Purpose (stated in ISO/IEC 27002:2022): keeps security and service delivery at the levels the supplier agreements set.
Steps that cite it
- KC-01 S5 Assess the vendor's assurance report
Evidence commonly asked for
- Statement of Applicability entry for control A.5.22, showing inclusion or justified exclusion, implementation status and the risks it treats
- Service performance reports and minutes of periodic supplier review meetings
- Records of supplier changes (new technology, locations, releases, sub-suppliers) with the organization's assessment of each
- Supplier audit reports and reviews of independent auditor or attestation reports, with tracked follow-up of findings
Accepted citation forms are listed on the answer format page.