Addressing Information Security Within Supplier Agreements
Addressing Information Security Within Supplier Agreements is an ISO/IEC 27001 reference control that asks an organisation to build security requirements into its contracts and agreements with suppliers. The aim is to make sure that when third parties handle or access the organisation's information, expectations around protecting that information are clearly agreed in writing. It is one of the controls an organisation may select when managing supplier relationships.
In the ISO/IEC 27001:2022 edition, this is Annex A control 5.20, located within the organisational controls theme; in the 2013 edition it corresponded to Annex A 15.1.2. As an Annex A reference control, its applicability is determined through the risk assessment and documented in the Statement of Applicability rather than being universally mandatory. The control calls for the organisation to establish and agree relevant information security requirements with each supplier, typically reflecting the type of access and information involved. It is distinct from the certifiable ISMS requirements in clauses 4 through 10, and implementation guidance for such controls is found in the companion standard ISO/IEC 27002. The specific requirements to include in any given agreement vary depending on scope, the nature of the supplier relationship, and the organisation's risk assessment.
Why it matters
Suppliers, vendors, and other third parties frequently need to access, process, or store an organisation's information in order to deliver their services. When those security expectations are left implicit or unwritten, the organisation loses a clear basis for holding the supplier accountable and may discover, often too late, that its information was handled in ways it never agreed to. Building security requirements into supplier agreements gives both parties a documented, shared understanding of how information must be protected across the relationship.
This control matters because supplier relationships extend an organisation's risk beyond its own boundaries. A control environment that is strong internally can still be undermined by a supplier whose obligations were never defined in the contract. By agreeing relevant information security requirements in writing, typically reflecting the type of access and information involved, an organisation creates an enforceable expectation and a reference point for monitoring, auditing, and remediation.
It is worth noting the limits of this control. Addressing security within supplier agreements is one of several Annex A reference controls that support supplier management, and its applicability is determined through the organisation's risk assessment and documented in the Statement of Applicability rather than being universally required. A well-drafted agreement establishes expectations but does not by itself guarantee that a supplier will meet them; it is typically paired with ongoing monitoring and other supplier-related controls to be effective.
Who it's relevant to
Inside Addressing Information Security Within Supplier Agreements
Common questions
Answers to the questions practitioners most commonly ask about Addressing Information Security Within Supplier Agreements.