Managing information security in the ICT supply chain
Summary
Processes and procedures shall be defined and implemented to manage the information security risks associated with the ICT products and services supply chain.
supply chainthird party
Read the full official text: https://www.iso.org/standard/27001
← Clause 5.20
A.5.20 Supplier agreements
Clause 5.22 →
Monitoring, review and change management of supplier services
Track ISO 27001 clause 5.21 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial