ISO 27001A.5 — Managing information security in the ICT supply chain
A.5.21
Managing information security in the ICT supply chain
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Manage information security risks in the ICT supply chain for supplier products and services.
Points of focus
- Supply-chain components identified for critical services
- Risks from subprocessors and upstream providers
- Integrity of software/firmware updates considered
- Monitoring of supply-chain incidents
Implementation notes
Map ICT supply chain for production: cloud, IdP, CI, observability, payment, support tools. Track subprocessors customers care about. Apply dependency scanning (A.8.8) and signed updates where feasible. When a upstream breach hits the news, run a short impact assessment ticket. Keep marketing trust pages in sync with the register.
Audit tip: For your primary cloud provider, show how a supplier security advisory would reach your on-call.
Evidence auditors typically request:
- Subprocessor list for the product
- Cloud shared-responsibility notes
- SBOM or dependency policy for critical apps
- Response notes to a supplier incident
Common gaps
- No idea who the vendor's subprocessors are
- CI dependencies unpinned and unmonitored
- Customer trust center lists stale
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.21 | This control |
| GDPR | Article 28 | Related GDPR articles for personal-data security or processor themes — not a compliance claim. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.21)
Frequently Asked Questions
Not universally under 27001, but dependency visibility is increasingly expected — start with critical services.
Proportionate to risk. Know your critical subprocessors; do not boil the ocean on every transitive library day one.
A.5.19 is supplier relationships broadly; A.5.21 focuses ICT supply-chain specifics for products/services.