Monitoring, review and change management of supplier services
Summary
The organisation shall regularly monitor, review, evaluate, and manage change in supplier information security practices and service delivery.
supplier monitoringthird party
Read the full official text: https://www.iso.org/standard/27001
← Clause 5.21
Managing information security in the ICT supply chain
Clause 5.23 →
Information security for use of cloud services
Track ISO 27001 clause 5.22 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial