ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.20: Addressing information security within supplier agreements

The information security requirements that matter for each supplier are to be set and agreed with that supplier, depending on the type of relationship. Purpose: make the agreed security level in each supplier relationship enforceable. Guidance: documented agreements should leave both parties clear about their security obligations. Terms to consider include: what information the supplier will receive or reach and by what means; its classification under the organization's scheme (5.10, 5.12, 5.13) and how that maps to the supplier's scheme; legal, regulatory and contractual obligations such as data protection, PII handling, intellectual property and copyright, and how compliance will be ensured; each party's duty to operate agreed controls (access control, performance review, monitoring, reporting, auditing) and the supplier's duty to meet the organization's requirements; acceptable and unacceptable use; how supplier staff are authorized and de-authorized, for instance an explicit list of named people; requirements for the supplier's ICT infrastructure with minimum requirements per information and access type; indemnities and remedies for failure; incident procedures, especially notification and joint remediation; training and awareness for specific procedures; subcontracting provisions such as flowing down obligations, a list of sub-suppliers and notice before changes; contacts including a security contact; lawful screening of supplier staff with responsibilities and what happens if screening is incomplete or raises concern; third-party attestations and independent reports on control effectiveness; a right to audit; periodic control effectiveness reports with timely correction of issues; defect and dispute resolution; backups matching the organization's needs for frequency, type and location; an alternate recovery site not exposed to the same threats, plus fallback controls; change management with advance notice and the option to refuse changes; physical security matching classification; protection in physical and logical transfer; termination terms on records, asset return, secure disposal and continuing confidentiality; secure destruction of the organization's information once no longer needed; and handover support at contract end to a new supplier or back in-house. A register of contracts, memoranda and information-sharing arrangements with outside parties (contracts, memoranda, information-sharing agreements) tracks where information goes, and agreements are regularly reviewed, validated and updated. Other information: agreements vary widely by organization and supplier type; ISO/IEC 27036 covers supplier agreements and ISO/IEC 19086 cloud service agreements.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 150 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 17 controls

  • AC-20 Use of External Systems
  • AC-20(1) Limits on Authorized Use
  • CP-7(3) Alternate Processing Site | Priority of Service (CP-7(3))
  • CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1))
  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • PS-7 External Personnel Security
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-4 Acquisition Process
  • SA-4(1) Acquisition Process | Functional Properties of Controls (SA-4(1))
  • SA-4(2) Acquisition Process | Design and Implementation Information for Controls (SA-4(2))
  • SA-4(9) Acquisition Process | Functions, Ports, Protocols, and Services in Use (SA-4(9))
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)
  • SR-8 Notification Agreements (SR-8)

FedRAMP Moderate · 17 controls

  • AC-20 Use of External Systems
  • AC-20(1) Limits on Authorized Use
  • CP-7(3) Alternate Processing Site | Priority of Service (CP-7(3))
  • CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1))
  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • PS-7 External Personnel Security
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-4 Acquisition Process
  • SA-4(1) Acquisition Process | Functional Properties of Controls (SA-4(1))
  • SA-4(2) Acquisition Process | Design and Implementation Information for Controls (SA-4(2))
  • SA-4(9) Acquisition Process | Functions, Ports, Protocols, and Services in Use (SA-4(9))
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)
  • SR-8 Notification Agreements (SR-8)

ISO 27701:2019 · 13 controls

  • 6.12 Supplier relationships
  • 6.12.1 Information security in supplier relationships
  • 7.2.6 Contracts with PII processors
  • 7.2.7 Joint PII controller
  • 7.5.1 Identify basis for PII transfer between jurisdictions
  • 7.5.2 Countries and international organizations to which PII can be transferred
  • 7.5.4 Records of PII disclosure to third parties
  • 8.2.1 Customer agreement
  • 8.2.5 Customer obligations
  • 8.5.1 Basis for PII transfer between jurisdictions
  • 8.5.3 Records of PII disclosure to third parties
  • 8.5.7 Engagement of a subcontractor to process PII
  • 8.5.8 Change of subcontractor to process PII

NIST SP 800-53 Rev 5 · 13 controls

  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
  • NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
  • NIST-CSF-GV.SC-09 Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
  • NIST-CSF-GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

PCI DSS 4.0 · 7 controls

  • 11.4.7 11.4.7 Multi-tenant providers support customer penetration testing
  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility
  • 12.8.3 12.8.3 Due diligence before engaging TPSPs
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs
  • 12.9.1 12.9.1 TPSP written acknowledgments to customers
  • 12.9.2 12.9.2 TPSP support for customer information requests
  • 3.7.9 3.7.9 Key guidance for service provider customers
  • ISM-0072 Documenting data security requirements in contracts
  • ISM-0141 Incident reporting obligations for providers
  • ISM-1451 Data types and ownership in contracts
  • ISM-1571 Right to verify provider compliance
  • ISM-1572 Data locations and change notification
  • ISM-1804 Break clauses for security failures

HIPAA Security Rule · 6 controls

SOC 2 · 5 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.1 P6.1 Disclosure to third parties with consent
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures

C5 (Germany) · 4 controls

  • C5-PI-02 Contractual agreements for the provision of data
  • C5-SSO-01 Policies and instructions for controlling and monitoring third parties
  • C5-SSO-04 Monitoring of compliance with requirements
  • C5-SSO-05 Exit strategy for the receipt of benefits

NIST SP 800-161 Rev 1 · 4 controls

  • ANSSI-HYG-01 Train Operational Teams in Information System Security
  • ANSSI-HYG-03 Control the Risks of Outsourced Information System Management
  • ANSSI-HYG-25 Secure Dedicated Network Interconnections with Partners

CIS Controls v8 · 3 controls

  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-15.5 Assess Service Providers
  • CIS-15.7 Securely Decommission Service Providers

ISO 27001:2022 · 3 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 8.30 Outsourced development

ISO/IEC 42001:2023 · 3 controls

  • A.10 Third-party and customer relationships
  • A.10.3 Suppliers
  • A.7.3 Acquisition of data

MTCS (Singapore) · 3 controls

  • 9.4 Third-party agreement
  • A.1 Disclosure: Right to audit
  • A.3 Disclosure: Data ownership

NIST SP 800-171 Rev 3 · 3 controls

  • 03.16.03 External System Services
  • 03.17.02 Acquisition Strategies, Tools, and Methods
  • 03.17.03 Supply Chain Requirements and Processes
  • CPS230-45 APRA Access Provisions in Formal Agreements
  • CPS230-50 Formal Agreement Content for Material Arrangements
  • MYHR-REG-4 Contracted service provider oversight
  • MYHR-REG-8 Copyright conditions on handling old records for operators and service providers
  • 19.5.24.C.06 19.5.24.C.06 Contracts cover provider merger, acquisition or failure
  • 22.1.23.C.03 22.1.23.C.03 Contract terms for provider merger, insolvency or termination
  • 0040 0040 Proportionate security terms in contracts and outsourcing
  • 0045 0045 Security arrangements for contract completion or termination
  • B.8 B.8 Personnel: involving people and choosing a security staffing model

APRA CPS 234 · 1 control

  • CPS234-P19 Policy Direction to All Responsible Parties
  • SEC.ADDON Reasonable care over third-party add-on partners
  • SEC03-BP09 Share resources securely with a third party
  • CFTC-SS-26 Own Resources or Contractual Arrangements to Meet the Recovery Objective

DORA · 1 control

GDPR · 1 control

ISO/IEC 27041:2015 · 1 control

  • 6.3 6.3 External assurance

NIS2 Directive · 1 control

  • Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider

NIST SP 800-172 · 1 control

  • 3.11.7e Supply Chain Risk Management Plan

NIST SP 800-218 · 1 control

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

NY DFS 23 NYCRR 500 · 1 control

  • §500.11 Third Party Service Provider Security Policy
  • P2-2.4.5 P2-2.4.5 Written agreements maintained

PTES · 1 control

  • PTES-1.3 Obtain written permission to test and address legal and third-party consent

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.20 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 150 it maps to, and the evidence behind each claim, over MCP and REST.