ICT Supply Chain Security (5.21)
ICT Supply Chain Security refers to managing the information security risks that arise when an organization relies on suppliers of information and communications technology (ICT) products, software, and managed services. Because the ICT supply chain spans the entire life cycle of hardware, software, and services across many interconnected vendors, this control asks organizations to set expectations with those suppliers and confirm they maintain an agreed level of security. It is one of the reference controls listed in Annex A of ISO/IEC 27001 (2022 revision), typically implemented to protect the organization's information and associated assets throughout supplier relationships.
Annex A Control 5.21 in the ISO/IEC 27001:2022 revision, with implementation guidance elaborated in ISO/IEC 27002:2022, addresses the establishment and enforcement of processes to identify and treat information security risks associated with the acquisition and use of ICT products and services from suppliers. Its stated purpose is to maintain an agreed level of information security in supplier relationships and to protect the organization's information and associated assets across the ICT supply chain, which encompasses the full life cycle of ICT hardware, software, and managed services within a globally interconnected ecosystem. As a reference control, 5.21 is selected through the Statement of Applicability and informed by the organization's risk assessment rather than being universally mandatory; the specific supplier requirements, contractual security clauses, and verification measures adopted vary depending on scope. The control does not, on its own, guarantee freedom from supply chain compromise; maintaining documentation under 5.21 typically serves to evidence that reasonable security steps were taken in securing the digital supply chain.
Why it matters
Modern organizations rarely build and operate their technology in isolation. They depend on a globally interconnected ecosystem of ICT suppliers that spans the entire life cycle of hardware, software, and managed services. A weakness introduced anywhere along that chain, by a component manufacturer, a software vendor, or a managed service provider, can propagate downstream into the organization's own environment. Annex A Control 5.21 exists because information security risk does not stop at the organizational boundary; it extends across every supplier relationship the organization relies upon.
Because the ICT supply chain is layered and interconnected, an organization often has limited direct visibility into the security practices of its suppliers and their sub-suppliers. Control 5.21 addresses this by asking organizations to set clear security expectations with ICT suppliers and to confirm that an agreed level of security is maintained throughout the relationship. This helps protect the organization's information and associated assets from risks that originate outside its own direct control.
It is important to be realistic about what this control achieves. Implementing 5.21 does not, on its own, guarantee freedom from a supply chain compromise. Rather, maintaining the supplier requirements, contractual clauses, and verification measures under this control typically serves to evidence that the organization took reasonable steps to secure its digital supply chain. In the event of a breach, that documentation can demonstrate that appropriate security expectations were established and monitored, even though no single control can eliminate the risk entirely.
Who it's relevant to
Inside ICT Supply Chain Security (5.21)
Common questions
Answers to the questions practitioners most commonly ask about ICT Supply Chain Security (5.21).