Skip to content
compliancebase
ISO 27001A.5 — Managing information security in the ICT supply chain

A.5.21

Managing information security in the ICT supply chain

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Manage information security risks in the ICT supply chain for supplier products and services.

Points of focus

  • Supply-chain components identified for critical services
  • Risks from subprocessors and upstream providers
  • Integrity of software/firmware updates considered
  • Monitoring of supply-chain incidents

Implementation notes

Map ICT supply chain for production: cloud, IdP, CI, observability, payment, support tools. Track subprocessors customers care about. Apply dependency scanning (A.8.8) and signed updates where feasible. When a upstream breach hits the news, run a short impact assessment ticket. Keep marketing trust pages in sync with the register.

Audit tip: For your primary cloud provider, show how a supplier security advisory would reach your on-call.

Evidence auditors typically request:

  • Subprocessor list for the product
  • Cloud shared-responsibility notes
  • SBOM or dependency policy for critical apps
  • Response notes to a supplier incident

Common gaps

  • No idea who the vendor's subprocessors are
  • CI dependencies unpinned and unmonitored
  • Customer trust center lists stale

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.21This control
GDPRArticle 28Related GDPR articles for personal-data security or processor themes — not a compliance claim.

Primary sources

Frequently Asked Questions

Not universally under 27001, but dependency visibility is increasingly expected — start with critical services.

Proportionate to risk. Know your critical subprocessors; do not boil the ocean on every transitive library day one.

A.5.19 is supplier relationships broadly; A.5.21 focuses ICT supply-chain specifics for products/services.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above