ISO 27002:2022 5.20: Addressing information security within supplier agreements
The information security requirements that matter for each supplier are to be set and agreed with that supplier, depending on the type of relationship. Purpose: make the agreed security level in each supplier relationship enforceable. Guidance: documented agreements should leave both parties clear about their security obligations. Terms to consider include: what information the supplier will receive or reach and by what means; its classification under the organization's scheme (5.10, 5.12, 5.13) and how that maps to the supplier's scheme; legal, regulatory and contractual obligations such as data protection, PII handling, intellectual property and copyright, and how compliance will be ensured; each party's duty to operate agreed controls (access control, performance review, monitoring, reporting, auditing) and the supplier's duty to meet the organization's requirements; acceptable and unacceptable use; how supplier staff are authorized and de-authorized, for instance an explicit list of named people; requirements for the supplier's ICT infrastructure with minimum requirements per information and access type; indemnities and remedies for failure; incident procedures, especially notification and joint remediation; training and awareness for specific procedures; subcontracting provisions such as flowing down obligations, a list of sub-suppliers and notice before changes; contacts including a security contact; lawful screening of supplier staff with responsibilities and what happens if screening is incomplete or raises concern; third-party attestations and independent reports on control effectiveness; a right to audit; periodic control effectiveness reports with timely correction of issues; defect and dispute resolution; backups matching the organization's needs for frequency, type and location; an alternate recovery site not exposed to the same threats, plus fallback controls; change management with advance notice and the option to refuse changes; physical security matching classification; protection in physical and logical transfer; termination terms on records, asset return, secure disposal and continuing confidentiality; secure destruction of the organization's information once no longer needed; and handover support at contract end to a new supplier or back in-house. A register of contracts, memoranda and information-sharing arrangements with outside parties (contracts, memoranda, information-sharing agreements) tracks where information goes, and agreements are regularly reviewed, validated and updated. Other information: agreements vary widely by organization and supplier type; ISO/IEC 27036 covers supplier agreements and ISO/IEC 19086 cloud service agreements.
This control maps to 150 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
NIST-CSF-GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
NIST-CSF-GV.SC-09 Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
NIST-CSF-GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.20 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.