ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.21: Managing information security in the ICT supply chain

Processes and procedures are to be defined and put in place to manage information security risks in the supply chain for ICT products and services. Purpose: keep security across the chain of ICT suppliers at the level agreed. Guidance: on top of the general supplier requirements, consider: setting security requirements for acquiring ICT products and services; requiring ICT service suppliers who subcontract to pass the organization's requirements down the chain; requiring ICT product suppliers to pass suitable security practices to the makers of components they buy in (subcontracted developers, hardware component makers); asking product suppliers to describe the software components inside their products; asking them to describe the security functions implemented and the configuration needed to run the product securely; monitoring and validating that delivered products and services meet stated requirements, for example through penetration testing or checking third-party attestations; identifying and documenting components critical to functionality that need closer scrutiny and follow-up when built externally, especially when further outsourced; getting assurance that critical parts can be followed back to where they came from; obtaining assurance that products work as expected with no unexpected or unwanted features; ensuring components are genuine and unaltered, using anti-tamper labels, hash checks or digital signatures, watching for out-of-specification behaviour as a sign of tampering or counterfeits, and guarding against tampering throughout design, development, integration, operation and maintenance; seeking assurance of required security levels through certification or evaluation schemes such as the arrangement for mutual recognition of Common Criteria certificates; agreeing rules for sharing supply chain issues and compromises with suppliers; and managing component life cycle and availability risk, including suppliers leaving the market or dropping components, with an alternative supplier and a way to transfer software and know-how. Other information: these practices sit on top of general security, quality, project and engineering practice; working with suppliers helps the organization understand the chain and influence it through agreements; ICT should come from reputable sources; the scope includes cloud services, IoT and hosting chains; ISO/IEC 27036-3 and software identification tags (ISO/IEC 19770-2) help.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 140 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 16 controls

  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-4(1) Acquisition Process | Functional Properties of Controls (SA-4(1))
  • SA-4(10) Use of Approved PIV Products
  • SA-4(2) Acquisition Process | Design and Implementation Information for Controls (SA-4(2))
  • SA-4(9) Acquisition Process | Functions, Ports, Protocols, and Services in Use (SA-4(9))
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SR-1 Policy and Procedures (SR-1)
  • SR-10 Inspection of Systems or Components (SR-10)
  • SR-11 Component Authenticity (SR-11)
  • SR-11(1) Component Authenticity | Anti-counterfeit Training (SR-11(1))
  • SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2))
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)

FedRAMP Moderate · 16 controls

  • IR-6(3) Incident Reporting | Supply Chain Coordination (IR-6(3))
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-4(1) Acquisition Process | Functional Properties of Controls (SA-4(1))
  • SA-4(10) Use of Approved PIV Products
  • SA-4(2) Acquisition Process | Design and Implementation Information for Controls (SA-4(2))
  • SA-4(9) Acquisition Process | Functions, Ports, Protocols, and Services in Use (SA-4(9))
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SR-1 Policy and Procedures (SR-1)
  • SR-10 Inspection of Systems or Components (SR-10)
  • SR-11 Component Authenticity (SR-11)
  • SR-11(1) Component Authenticity | Anti-counterfeit Training (SR-11(1))
  • SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair (SR-11(2))
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-5 Acquisition Strategies, Tools, and Methods (SR-5)
  • SR-6 Supplier Assessments and Reviews (SR-6)

NIST SP 800-53 Rev 5 · 12 controls

  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
  • NIST-CSF-GV.SC-04 Suppliers are known and prioritized by criticality
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
  • NIST-CSF-GV.SC-09 Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
  • NIST-CSF-GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
  • ISM-0280 Preferring PP-based evaluated products
  • ISM-0731 Oversight of cyber supply chain risk management
  • ISM-0938 Selecting secure-by-design user application vendors
  • ISM-1452 Supply chain risk assessment
  • ISM-1460 Secure-by-design vendors for isolation mechanisms
  • ISM-1631 Identifying suppliers for systems
  • ISM-1743 Operating system vendor selection
  • ISM-1791 Integrity checks at acceptance
  • ISM-1826 Server application vendor selection
  • ISM-2082 Using third-party cryptographic bills of materials

PCI DSS 4.0 · 7 controls

  • 12.5.2.1 12.5.2.1 Six-monthly scope confirmation for service providers
  • 12.8.1 12.8.1 List of third-party service providers
  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility
  • 12.8.3 12.8.3 Due diligence before engaging TPSPs
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs
  • 6.3.2 6.3.2 Inventory of bespoke software and components

CIS Controls v8 · 6 controls

  • CIS-15.1 Establish and Maintain an Inventory of Service Providers
  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-15.5 Assess Service Providers
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CPS230-39 Register of Material Service Providers
  • CPS230-43 Due Diligence Before Entering or Modifying a Material Arrangement
  • CPS230-P48 Required Content of the Service Provider Management Policy
  • 47 Para 47 Required content of the service provider policy, including fourth parties

ISO 22301:2019 · 4 controls

  • 4.2.1 General
  • 6.1.2 Addressing risks and opportunities
  • 8.2.3 Risk assessment
  • 8.3.2 Identification of strategies and solutions

NIST SP 800-161 Rev 1 · 4 controls

NIST SP 800-218 · 4 controls

SOC 2 · 4 controls

  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures

C5 (Germany) · 3 controls

  • C5-SSO-01 Policies and instructions for controlling and monitoring third parties
  • C5-SSO-02 Risk assessment of service providers and suppliers
  • C5-SSO-03 Directory of service providers and suppliers

HIPAA Security Rule · 3 controls

ISO 27001:2022 · 3 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the information and communication technology (ICT) supply chain

ISO 27701:2019 · 3 controls

  • 6.12 Supplier relationships
  • 6.12.1 Information security in supplier relationships
  • 8.5.8 Change of subcontractor to process PII

NIST SP 800-171 Rev 3 · 3 controls

  • 03.17.01 Supply Chain Risk Management Plan
  • 03.17.02 Acquisition Strategies, Tools, and Methods
  • 03.17.03 Supply Chain Requirements and Processes

DORA · 2 controls

  • DORA-Art.28 ICT third-party risk: general principles
  • DORA-Art.29 Preliminary assessment of ICT concentration risk at entity level

NIST SP 800-172 · 2 controls

  • 3.14.3e Include Systems in Scope of Enhanced Requirements or Segregate into Purpose-Specific Networks
  • 3.4.1e Authoritative Source for Software and Firmware
  • ANSSI-HYG-42 Prefer Products and Services Qualified by ANSSI

APRA CPS 234 · 1 control

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • SEC.SUPPLY Supply chain overview with the functional role of each participant
  • DS-2 Ensure software supply chain security
  • CFTC-SS-31 Testing Covers Outsourced Resources and Tester Independence from Providers

GDPR · 1 control

ISO/IEC 42001:2023 · 1 control

  • A.10 Third-party and customer relationships

MTCS (Singapore) · 1 control

  • A.8 Disclosure: Third-party dependency

NIS2 Directive · 1 control

  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments
  • INV-SUPPLY Map cryptographic suppliers and dependencies
  • 12.7.15.C.01 12.7.15.C.01 Tenderers disclose export restrictions and supply chain compliance
  • TSA-SD-14 Supply chain and third party risk
  • MTSA-Supply-Chain Supply Chain Risk Management for Security Systems

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.21 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 140 it maps to, and the evidence behind each claim, over MCP and REST.