ISO 27002:2022 5.21: Managing information security in the ICT supply chain
Processes and procedures are to be defined and put in place to manage information security risks in the supply chain for ICT products and services. Purpose: keep security across the chain of ICT suppliers at the level agreed. Guidance: on top of the general supplier requirements, consider: setting security requirements for acquiring ICT products and services; requiring ICT service suppliers who subcontract to pass the organization's requirements down the chain; requiring ICT product suppliers to pass suitable security practices to the makers of components they buy in (subcontracted developers, hardware component makers); asking product suppliers to describe the software components inside their products; asking them to describe the security functions implemented and the configuration needed to run the product securely; monitoring and validating that delivered products and services meet stated requirements, for example through penetration testing or checking third-party attestations; identifying and documenting components critical to functionality that need closer scrutiny and follow-up when built externally, especially when further outsourced; getting assurance that critical parts can be followed back to where they came from; obtaining assurance that products work as expected with no unexpected or unwanted features; ensuring components are genuine and unaltered, using anti-tamper labels, hash checks or digital signatures, watching for out-of-specification behaviour as a sign of tampering or counterfeits, and guarding against tampering throughout design, development, integration, operation and maintenance; seeking assurance of required security levels through certification or evaluation schemes such as the arrangement for mutual recognition of Common Criteria certificates; agreeing rules for sharing supply chain issues and compromises with suppliers; and managing component life cycle and availability risk, including suppliers leaving the market or dropping components, with an alternative supplier and a way to transfer software and know-how. Other information: these practices sit on top of general security, quality, project and engineering practice; working with suppliers helps the organization understand the chain and influence it through agreements; ICT should come from reputable sources; the scope includes cloud services, IoT and hosting chains; ISO/IEC 27036-3 and software identification tags (ISO/IEC 19770-2) help.
This control maps to 140 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
NIST-CSF-GV.SC-04 Suppliers are known and prioritized by criticality
NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
NIST-CSF-GV.SC-09 Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
NIST-CSF-GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.21 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.