ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.22: Monitoring, review and change management of supplier services

On a regular basis the organization is to monitor, review and evaluate suppliers' security practices and service delivery and to manage changes to them. Purpose: keep information security and service delivery at the level set in the supplier agreements. Guidance: this oversight should confirm that the security terms are honoured, that incidents and problems are handled properly and that changes in the supplier's services or business situation do not disrupt delivery. A relationship management process should: check service performance against the agreement; track supplier-side changes such as service enhancements, new applications and systems, revised policies and procedures, and new or changed controls to fix incidents or improve security; track changes in the services themselves such as network changes, new technologies, new products, versions or releases, new development tools and environments, relocated facilities, and changed or added sub-suppliers or subcontracting; review supplier service reports and hold the progress meetings the agreement calls for; audit suppliers and sub-suppliers, alongside independent auditor reports where available, and follow up findings; exchange and review incident information as agreed; examine supplier audit trails and records of security events, operational problems, failures, fault tracing and disruptions; respond to and manage identified events or incidents; identify and manage vulnerabilities; review the security of the supplier's own supplier relationships; make sure the supplier keeps enough capacity and workable plans to hold agreed continuity levels after major failure or disaster (see 5.29 and 5.30, 5.35 and 5.36, and 8.14); make sure suppliers name people responsible for checking and enforcing compliance with the agreement; and regularly evaluate whether the supplier keeps adequate security. A designated person or team owns each relationship, with the technical skills and resources to check that requirements, especially security ones, are met, and deficiencies trigger appropriate action. ISO/IEC 27036-3 gives more detail.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 113 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-03 Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
  • NIST-CSF-GV.SC-04 Suppliers are known and prioritized by criticality
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-GV.SC-08 Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
  • NIST-CSF-GV.SC-09 Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
  • NIST-CSF-GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

NIST SP 800-53 Rev 5 · 11 controls

FedRAMP High · 8 controls

  • CA-2(3) Control Assessments | Leveraging Results from External Organizations (CA-2(3))
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-9 External System Services
  • SA-9(2) Identification of Functions, Ports, Protocols, and Services
  • SR-1 Policy and Procedures (SR-1)
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-6 Supplier Assessments and Reviews (SR-6)

FedRAMP Moderate · 8 controls

  • CA-2(3) Control Assessments | Leveraging Results from External Organizations (CA-2(3))
  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • SA-9 External System Services
  • SA-9(2) Identification of Functions, Ports, Protocols, and Services
  • SR-1 Policy and Procedures (SR-1)
  • SR-2 Supply Chain Risk Management Plan (SR-2)
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • SR-6 Supplier Assessments and Reviews (SR-6)

PCI DSS 4.0 · 7 controls

  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews
  • 12.5.2.1 12.5.2.1 Six-monthly scope confirmation for service providers
  • 12.5.3 12.5.3 Scope review after significant organisational change
  • 12.8.3 12.8.3 Due diligence before engaging TPSPs
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs
  • 12.9.2 12.9.2 TPSP support for customer information requests

SOC 2 · 6 controls

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • ISM-1570 IRAP assessment of cloud providers
  • ISM-1737 Managed service register contents
  • ISM-1738 Exercising the right to verify compliance
  • ISM-1794 Notice of provider arrangement changes
  • ISM-1971 ASD assessment of TOP SECRET managed services

ISO 27701:2019 · 5 controls

  • 5.7 Performance evaluation
  • 6.12 Supplier relationships
  • 6.12.2 Supplier service delivery management
  • 8.5.7 Engagement of a subcontractor to process PII
  • 8.5.8 Change of subcontractor to process PII

ISO 22301:2019 · 4 controls

  • 6.3 Planning changes to the business continuity management system
  • 8.1 Operational planning and control
  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.3 Management review

NIST SP 800-161 Rev 1 · 4 controls

APRA CPS 234 · 3 controls

  • CPS234-27 Internal Audit Assessment of Third Party Control Assurance
  • CPS234-P22 Evaluation of Third Party Control Design
  • CPS234-P28 Assessment of Reliance on Third Party Control Testing

CIS Controls v8 · 3 controls

ISO 27001:2022 · 3 controls

  • 5.19 Information security in supplier relationships
  • 5.22 Monitoring, review and change management of supplier services
  • 8.30 Outsourced development

ISO/IEC 42001:2023 · 3 controls

  • 9.1 Monitoring, measurement, analysis and evaluation
  • 9.3 Management review
  • A.10 Third-party and customer relationships
  • 0041 0041 Ensure providers and subcontractors comply with relevant PSPF requirements
  • 0044 0044 Monitor contract security terms over the contract life
  • 0047 0047 Manage and reassess contractual security risk over the contract life
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • CPS230-47 Monitoring and Senior Management Reporting on Material Arrangements

C5 (Germany) · 2 controls

  • C5-SSO-04 Monitoring of compliance with requirements
  • C5-SSO-05 Exit strategy for the receipt of benefits

HIPAA Security Rule · 2 controls

MTCS (Singapore) · 2 controls

  • 10.6 Third-party compliance
  • 9.5 Third-party delivery management

NIS2 Directive · 2 controls

  • Art.21.2.d Supply chain security, covering the relationship with each direct supplier and service provider
  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments
  • ANSSI-HYG-03 Control the Risks of Outsourced Information System Management

APPI · 1 control

  • CFTC-SS-30 Outsourcing with Retention of Complete Responsibility

DORA · 1 control

GDPR · 1 control

NIST SP 800-172 · 1 control

  • 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring
  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)
  • 5.8.61.C.03 5.8.61.C.03 Use assurance reports and certifications to inform risk
  • P2-2.4.4 P2-2.4.4 Third parties' agreed responsibilities verified periodically

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.22 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 113 it maps to, and the evidence behind each claim, over MCP and REST.