ISO 27002:2022 5.22: Monitoring, review and change management of supplier services
On a regular basis the organization is to monitor, review and evaluate suppliers' security practices and service delivery and to manage changes to them. Purpose: keep information security and service delivery at the level set in the supplier agreements. Guidance: this oversight should confirm that the security terms are honoured, that incidents and problems are handled properly and that changes in the supplier's services or business situation do not disrupt delivery. A relationship management process should: check service performance against the agreement; track supplier-side changes such as service enhancements, new applications and systems, revised policies and procedures, and new or changed controls to fix incidents or improve security; track changes in the services themselves such as network changes, new technologies, new products, versions or releases, new development tools and environments, relocated facilities, and changed or added sub-suppliers or subcontracting; review supplier service reports and hold the progress meetings the agreement calls for; audit suppliers and sub-suppliers, alongside independent auditor reports where available, and follow up findings; exchange and review incident information as agreed; examine supplier audit trails and records of security events, operational problems, failures, fault tracing and disruptions; respond to and manage identified events or incidents; identify and manage vulnerabilities; review the security of the supplier's own supplier relationships; make sure the supplier keeps enough capacity and workable plans to hold agreed continuity levels after major failure or disaster (see 5.29 and 5.30, 5.35 and 5.36, and 8.14); make sure suppliers name people responsible for checking and enforcing compliance with the agreement; and regularly evaluate whether the supplier keeps adequate security. A designated person or team owns each relationship, with the technical skills and resources to check that requirements, especially security ones, are met, and deficiencies trigger appropriate action. ISO/IEC 27036-3 gives more detail.
This control maps to 113 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
NIST-CSF-GV.SC-04 Suppliers are known and prioritized by criticality
NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
NIST-CSF-GV.SC-09 Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
NIST-CSF-GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.22 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.