Skip to main content
Category: Supplier and Third-Party

Addressing Information Security Within Supplier Agreements

Also known as: Information Security in Supplier Agreements, ISO 27001 Annex A 5.20, Annex A 15.1.2 (2013 edition)
Simply put

Addressing Information Security Within Supplier Agreements is an ISO/IEC 27001 reference control that asks an organisation to build security requirements into its contracts and agreements with suppliers. The aim is to make sure that when third parties handle or access the organisation's information, expectations around protecting that information are clearly agreed in writing. It is one of the controls an organisation may select when managing supplier relationships.

Formal definition

In the ISO/IEC 27001:2022 edition, this is Annex A control 5.20, located within the organisational controls theme; in the 2013 edition it corresponded to Annex A 15.1.2. As an Annex A reference control, its applicability is determined through the risk assessment and documented in the Statement of Applicability rather than being universally mandatory. The control calls for the organisation to establish and agree relevant information security requirements with each supplier, typically reflecting the type of access and information involved. It is distinct from the certifiable ISMS requirements in clauses 4 through 10, and implementation guidance for such controls is found in the companion standard ISO/IEC 27002. The specific requirements to include in any given agreement vary depending on scope, the nature of the supplier relationship, and the organisation's risk assessment.

Why it matters

Suppliers, vendors, and other third parties frequently need to access, process, or store an organisation's information in order to deliver their services. When those security expectations are left implicit or unwritten, the organisation loses a clear basis for holding the supplier accountable and may discover, often too late, that its information was handled in ways it never agreed to. Building security requirements into supplier agreements gives both parties a documented, shared understanding of how information must be protected across the relationship.

This control matters because supplier relationships extend an organisation's risk beyond its own boundaries. A control environment that is strong internally can still be undermined by a supplier whose obligations were never defined in the contract. By agreeing relevant information security requirements in writing, typically reflecting the type of access and information involved, an organisation creates an enforceable expectation and a reference point for monitoring, auditing, and remediation.

It is worth noting the limits of this control. Addressing security within supplier agreements is one of several Annex A reference controls that support supplier management, and its applicability is determined through the organisation's risk assessment and documented in the Statement of Applicability rather than being universally required. A well-drafted agreement establishes expectations but does not by itself guarantee that a supplier will meet them; it is typically paired with ongoing monitoring and other supplier-related controls to be effective.

Who it's relevant to

GRC and compliance managers
Those responsible for the ISMS need to decide, through the risk assessment, whether this control applies and document that decision in the Statement of Applicability. They coordinate the security requirements that flow into supplier contracts and ensure the approach aligns with the organisation's overall supplier-management controls.
Procurement and vendor management teams
Because the control is delivered through contracts and agreements, procurement teams play a central role in embedding agreed information security requirements into supplier terms and ensuring those requirements reflect the type of access and information involved in each relationship.
Legal and contracts staff
Legal teams translate the identified security requirements into enforceable contractual language. Their involvement helps ensure that expectations around protecting information are clearly agreed in writing and can serve as a reference point for accountability and remediation.
ISO 27001 auditors and certification bodies
Auditors assessing an ISMS against ISO/IEC 27001 review whether a selected control such as 5.20 has been implemented consistently with the Statement of Applicability and the underlying risk assessment. They evaluate the evidence within the defined scope of the ISMS rather than certifying the organisation's suppliers directly.
Security engineers and operations teams
Those who manage day-to-day supplier access rely on the agreed requirements to understand what a supplier is permitted to do and how information must be protected, supporting the monitoring activities that typically accompany contractual obligations.

Inside Addressing Information Security Within Supplier Agreements

Supplier Agreement Security Clauses
Contractual provisions that establish the security obligations a supplier must meet, typically addressing confidentiality, access controls, incident notification, and the handling of information the supplier processes or accesses on behalf of the organization. The specific clauses included depend on the scope of the relationship and the risk assessment.
Scope of Access Definition
A statement of what information, systems, or facilities the supplier may access, and under what conditions. Defining this boundary helps clarify which controls apply to the supplier and limits the exposure attributed to the relationship.
Incident Notification and Response Requirements
Provisions requiring the supplier to notify the organization of security incidents affecting shared or processed information, often including expectations around timelines and cooperation. The exact requirements vary by contract and by the sensitivity of the information involved.
Right to Audit or Evidence of Assurance
Terms that allow the organization to verify a supplier's security posture, whether through direct audit rights or through the supplier providing independent assurance such as a SOC 2 report or evidence of ISO 27001 certification for the relevant scope. Reliance on such evidence typically depends on the scope covered by the report or certificate.
Subcontractor and Fourth-Party Provisions
Clauses addressing whether and how a supplier may engage its own subcontractors, and what security expectations flow down to them. This helps manage risk introduced beyond the immediate supplier relationship.
Framework Reference Points
In ISO/IEC 27001, supplier relationship considerations are addressed through Annex A reference controls selected via the Statement of Applicability and informed by risk assessment. In a SOC 2 examination, supplier and vendor management activities are typically evaluated against the Security category (the Common Criteria), depending on scope. Neither treatment is interchangeable with the other.

Common questions

Answers to the questions practitioners most commonly ask about Addressing Information Security Within Supplier Agreements.

Does ISO 27001 mandate a specific set of security clauses that must appear in every supplier agreement?
No. Addressing security within supplier agreements is expressed as an Annex A reference control, and Annex A controls are selected via the Statement of Applicability informed by a risk assessment. The certifiable requirements sit in clauses 4 through 10. Whether and how you address security in supplier agreements, and what terms you include, typically depends on your scope, the nature of the supplier relationship, and the risks identified, rather than a fixed universal checklist.
Is having security clauses in supplier agreements a SOC 2 requirement in the same way it is under ISO 27001?
The two frameworks approach this differently and should not be conflated. In a SOC 2 examination, vendor and supplier considerations are evaluated against the applicable Trust Services Criteria (with Security, the Common Criteria, being the only required category) as part of a CPA firm's attestation. This is not the same as an ISO 27001 Annex A reference control selected through a Statement of Applicability. Satisfying supplier-related expectations in one framework does not automatically satisfy the other, since mapping between them is partial.
What kinds of terms are typically considered when addressing security within a supplier agreement?
In most engagements, organizations consider terms covering the supplier's security responsibilities, handling and protection of relevant information, expectations around incident notification, and any rights to assess or obtain assurance over the supplier's controls. The specific terms appropriate for a given agreement depend on scope, the risk assessment, and the sensitivity of the information or services involved, so the exact provisions vary by relationship.
How do we decide which suppliers need security provisions in their agreements?
This is typically driven by risk. A risk assessment can help identify which suppliers access, process, or affect information within the ISMS scope, and which relationships warrant more detailed security terms. Depending on scope, higher-risk or more integrated suppliers generally receive more attention, while the depth of provisions is calibrated to the assessed risk rather than applied uniformly.
How does this control relate to the broader guidance available in ISO 27002?
ISO 27001 Annex A lists reference controls at a high level, while ISO 27002 provides implementation guidance for those controls. Organizations often consult ISO 27002 for practical direction on how to approach supplier agreement provisions, but ISO 27002 is guidance rather than a certifiable standard. The certification is against ISO 27001, and how you implement the control is informed by your Statement of Applicability and risk assessment.
What are the limitations of relying on security clauses in supplier agreements?
Contractual terms define expectations but do not by themselves guarantee that a supplier operates securely or that no incidents will occur. Depending on scope, organizations often complement agreement terms with ongoing monitoring or assurance activities. It is also worth noting that certification or attestation outcomes cover only the defined scope and period assessed; an ISO 27001 certificate covers only the defined ISMS scope, and a SOC 2 report attests only to the controls and period covered.

Common misconceptions

Obtaining a SOC 2 report or ISO 27001 certificate from a supplier proves the entire supplier relationship is secure.
A SOC 2 report attests only to the controls and the review period covered, and does not guarantee freedom from breaches. An ISO 27001 certificate covers only the defined scope of the supplier's ISMS. Practitioners should confirm that the specific services and information they rely on fall within the scope of the report or certificate before placing reliance on it.
There is a single mandatory set of security clauses that must appear in every supplier agreement.
The clauses included typically depend on the scope of the relationship, the results of risk assessment, and applicable criteria. Rather than a universal mandatory template, appropriate provisions are selected based on the risk the supplier introduces and the frameworks in use.
If a supplier satisfies one framework, it automatically meets the supplier-related expectations of the other.
Mapping between SOC 2 and ISO 27001 is possible but partial. Satisfying supplier-related requirements under one framework does not automatically satisfy the other, because the Trust Services Criteria and ISO 27001's clauses and Annex A controls are structured and assessed differently.

Best practices

Define the scope of each supplier's access to information and systems within the agreement so that applicable security obligations are clear and bounded.
Include the right to obtain evidence of the supplier's security posture, and verify that any SOC 2 report or ISO 27001 certificate provided actually covers the services and information you depend on.
Specify incident notification expectations in the agreement, including cooperation obligations, tailored to the sensitivity of the information the supplier handles.
Address subcontractor and fourth-party arrangements so that relevant security expectations flow down beyond the immediate supplier.
Base the selection of security clauses on a documented risk assessment of the relationship rather than applying a one-size-fits-all template.
Reassess supplier assurance periodically, recognizing that a report or certificate covers only a defined period or scope and does not guarantee ongoing freedom from breaches.