A.5.21A.5 Organizational controls

Managing information security in the ICT supply chain

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.5.21 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Manage the security risks that come with buying and using ICT products and services through a supply chain.

How to meet this control

In short: Manage security risks across the ICT product and service supply chain.

  1. Step 01Define ICT security acquisition requirements and include them in tenders and purchase contracts
  2. Step 02Request ISO 27001, SOC 2 or equivalent attestations from key ICT suppliers and review them on renewal
  3. Step 03Ask suppliers to disclose product components and to flow your requirements down to their sub-contractors
  4. Step 04Validate critical components through penetration testing, attestations or integrity checks such as signatures and hashes
  5. Step 05Identify critical components and plan for obsolescence by mapping alternative suppliers

Tip: Ask key suppliers for their own ISO 27001/SOC 2 evidence.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Spell out security requirements that apply when acquiring ICT products or services
  • ›Require suppliers to pass your security expectations down to their own sub-contractors
  • ›Ask suppliers to disclose the software components and security functions built into their products
  • ›Validate that delivered products and services meet requirements, via penetration testing or third-party attestations
  • ›Track which components are critical and verify their origin can be traced through the chain
  • ›Use anti-tamper measures such as cryptographic hashes or digital signatures to confirm components are genuine
  • ›Seek assurance of required security levels via certification or schemes like Common Criteria
  • ›Plan for component obsolescence by identifying alternative suppliers and transfer processes

Audit evidence to keep

  • - ICT acquisition requirements embedded in tenders or purchase contracts
  • - Supplier attestations (ISO 27001, SOC 2) for key ICT products and services
  • - Records validating delivered components meet requirements (testing or signatures)
  • - Documentation of critical components and supply-chain contingency plans

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.5.21. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all organizational controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.