A.5.20 Supplier agreements
Summary
Security requirements are established and agreed with each supplier directly, evidenced by the supplier's own completed due-diligence response rather than only an internal assessment on their behalf.
annex asupplier agreementsdue diligencethird party
Read the full official text: https://www.iso.org/standard/27001
← Clause 5.19
Information security in supplier relationships
Clause 5.21 →
Managing information security in the ICT supply chain
Track ISO 27001 clause 5.20 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial