ISO 27001:2022
Organizational controls – ISO 27001:2022

ISO 27001:2022 5.22: Monitoring, review and change management of supplier services

On a regular basis the organization is to monitor, review and evaluate suppliers' security practices and service delivery and to manage changes to them. Purpose (stated in ISO/IEC 27002:2022): keeps security and service delivery at the levels the supplier agreements set. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.22.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 129 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-GV.OC-05 Outcomes, capabilities, and services that the organization depends on are understood and communicated
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
  • NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
  • NIST-CSF-GV.SC-04 Suppliers are known and prioritized by criticality
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
  • NIST-CSF-GV.SC-09 Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
  • NIST-CSF-GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

NIST SP 800-53 Rev 5 · 14 controls

  • NIST800-AU-16 AU-16 Cross-organizational Audit Logging
  • NIST800-CA-7 CA-7 Continuous Monitoring
  • NIST800-PM-31 PM-31 Continuous Monitoring Strategy
  • NIST800-PM-6 PM-6 Measures of Performance
  • NIST800-SA-9 SA-9 External System Services
  • NIST800-SR-1 SR-1 Policy and Procedures
  • NIST800-SR-10 SR-10 Inspection of Systems or Components
  • NIST800-SR-2 SR-2 Supply Chain Risk Management Plan
  • NIST800-SR-3 SR-3 Supply Chain Controls and Processes
  • NIST800-SR-5 SR-5 Acquisition Strategies, Tools, and Methods
  • NIST800-SR-6 SR-6 Supplier Assessments and Reviews
  • SP800-53-CA Assessment, Authorization, and Monitoring Family
  • SP800-53-SA System and Services Acquisition Family
  • SP800-53-SR Supply Chain Risk Management Family

FedRAMP High · 13 controls

  • CA-3 Information Exchange
  • CA-7 Continuous Monitoring
  • CM-3(4) Security and Privacy Representatives
  • MA-4 Nonlocal Maintenance
  • PS-7 External Personnel Security
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-22 Unsupported System Components (SA-22)
  • SA-9 External System Services
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-2(1) Supply Chain Risk Management Plan | Establish SCRM Team (SR-2(1))
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)

FedRAMP Moderate · 13 controls

  • CA-3 Information Exchange
  • CA-7 Continuous Monitoring
  • CM-3(4) Security and Privacy Representatives
  • MA-4 Nonlocal Maintenance
  • PS-7 External Personnel Security
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-22 Unsupported System Components (SA-22)
  • SA-9 External System Services
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-2(1) Supply Chain Risk Management Plan | Establish SCRM Team (SR-2(1))
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)

PCI DSS 4.0 · 10 controls

  • 11.4.6 11.4.6 Service provider segmentation testing every six months
  • 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement
  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews
  • 12.5.2 12.5.2 Annual and change-driven scope confirmation
  • 12.5.2.1 12.5.2.1 Six-monthly scope confirmation for service providers
  • 12.5.3 12.5.3 Scope review after significant organisational change
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs
  • 12.9.2 12.9.2 TPSP support for customer information requests

CIS Controls v8 · 9 controls

  • CIS-15.1 Establish and Maintain an Inventory of Service Providers
  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-15.5 Assess Service Providers
  • CIS-15.6 Monitor Service Providers
  • CIS-15.7 Securely Decommission Service Providers
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-3.8 Document Data Flows
  • CIS-8.12 Collect Service Provider Logs

ISO 27701:2019 · 5 controls

  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 6.12 Supplier relationships
  • 6.12.2 Supplier service delivery management
  • 6.15.2 Information security reviews
  • 8.5.8 Change of subcontractor to process PII

SOC 2 · 5 controls

  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties

ISO 27002:2022 · 4 controls

  • 5.19 Information security in supplier relationships
  • 5.22 Monitoring, review and change management of supplier services
  • 8.21 Security of network services
  • 8.30 Outsourced development

NIST SP 800-161 Rev 1 · 4 controls

ISO/IEC 42001:2023 · 3 controls

  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.3 Management review
  • A.10 Third-party and customer relationships
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • CPS230-47 Monitoring and Senior Management Reporting on Material Arrangements

APRA CPS 234 · 2 controls

  • CPS234-27 Internal Audit Assessment of Third Party Control Assurance
  • CPS234-P28 Assessment of Reliance on Third Party Control Testing

C5 (Germany) · 2 controls

  • C5-SSO-04 Monitoring of compliance with requirements
  • C5-SSO-05 Exit strategy for the receipt of benefits

COBIT 2019 · 2 controls

  • APO10.05 APO10.05 Monitor vendor performance and compliance
  • DSS01.02 DSS01.02 Manage outsourced I&T services

HIPAA Security Rule · 2 controls

ISO 27001:2013 · 2 controls

  • A.15.2.1 Monitoring and review of supplier services
  • A.15.2.2 Managing changes to supplier services

NIS2 Directive · 2 controls

  • Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider
  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments

NIST SP 800-171 Rev 3 · 2 controls

  • 03.16.03 External System Services
  • 03.17.03 Supply Chain Requirements and Processes

APPI · 1 control

  • CFTC-SS-30 Outsourcing with Retention of Complete Responsibility

DORA · 1 control

EU AI Act · 1 control

  • EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

GDPR · 1 control

ISO 22301:2019 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation

NIST SP 800-172 · 1 control

  • 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring
  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 5.22 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 129 it maps to, and the evidence behind each claim, over MCP and REST.