Addressing information security within supplier agreements
Purpose
Maintain an agreed level of security by setting and agreeing security requirements with each supplier.
How to meet this control
In short: Establish relevant security requirements in agreements with suppliers.
- Step 01Use a standard security and data protection addendum or DPA for any vendor handling your data
- Step 02Specify the information involved, its classification, permitted access methods and acceptable use in the agreement
- Step 03Include incident notification timeframes, audit or attestation rights and breach obligations in the contract
- Step 04Define authorisation and removal procedures for supplier personnel who access your assets
- Step 05Address sub-contracting controls and secure handling of data at termination of the relationship
Tip: Use a standard security/DPA addendum for vendors touching your data.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Establish and document supplier agreements so both parties understand their obligations
- ›Describe the information involved and the methods of providing or accessing it
- ›Include classification of information and map your scheme to the supplier scheme
- ›Spell out legal, regulatory and contractual requirements, including data protection and intellectual property
- ›Require each party to implement an agreed set of controls and define acceptable use rules
- ›Set authorisation and removal procedures for supplier personnel accessing your assets
- ›Define incident management, notification, audit rights and assurance or third-party attestation requirements
- ›Address sub-contracting controls and ensure secure handling at termination of the relationship
- ›Keep a register of agreements with external parties and review the agreements periodically to confirm they are still needed and carry the right security clauses
Audit evidence to keep
- - Signed supplier agreements containing information security clauses
- - Standard security or data protection addendum used with vendors
- - Contract terms covering incident notification, audit rights and sub-contracting
- - Evidence the security requirements match the classification of data shared
Common mistakes
- - Treating all suppliers as equal risk
- - Collecting vendor reports but not reviewing exceptions
- - Forgetting exit, deletion, sub-processor, and change-notice terms
Owner, cadence, and proof
Assign one accountable owner for A.5.20. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.