Skip to main content
Category: Supplier and Third-Party

Managing Information Security in the ICT Supply Chain

Also known as: ISO 27001 Annex A 5.21, ICT Supply Chain Security Control, Annex A Control 5.21
Simply put

This is an ISO/IEC 27001 reference control that addresses the security risks that come from the suppliers, partners, and service providers who help produce or deliver an organization's information and communications technology (ICT) products and services. Because ICT products and services move through a global and distributed chain of vendors, this control asks organizations to define processes that identify and reduce the security risks introduced along that chain. In practice, it helps ensure that risks tied to third parties in the ICT supply chain are recognized and managed rather than assumed to be safe.

Formal definition

In the ISO/IEC 27001:2022 revision, this control appears as Annex A 5.21, one of the reference controls listed in Annex A that organizations may select through their Statement of Applicability and risk assessment rather than a clause 4-10 ISMS requirement that is inherently mandatory. It calls for processes and procedures to be defined and implemented to manage information security risks associated with the ICT products and services supply chain, with the objective of ensuring that risks associated with suppliers, partners, and service providers are identified and addressed. This aligns conceptually with the broader discipline of ICT supply chain risk management, described as the process of identifying, assessing, and mitigating risks associated with the global and distributed nature of ICT product and service supply chains. The precise applicability, implementation depth, and evidence expected depend on scope, the organization's risk assessment, and the certification body; as an Annex A reference control, its selection and configuration vary by engagement, and inclusion is determined via the Statement of Applicability rather than universally required.

Why it matters

Modern ICT products and services rarely originate from a single source. As described in the evidence, the ICT supply chain is the sequence of actions that transform raw resources into products and services such as computer hardware and software, and this chain is global and distributed by nature. That distribution means an organization's security posture depends not only on its own controls but also on the suppliers, partners, and service providers embedded throughout the chain. A weakness introduced by any of those third parties can propagate downstream, which is why Annex A 5.21 asks organizations to treat supply chain risk as something to be actively identified and managed rather than assumed to be safe.

The discipline this control supports, ICT supply chain risk management, is defined as the process of identifying, assessing, and mitigating the risks associated with the global and distributed nature of ICT product and service supply chains. Recognition of these risks at a national level is reflected in public-private efforts, such as the CISA-associated partnership charged with identifying and developing consensus risk management strategies to enhance global ICT supply chain security. This underscores that supply chain security is treated as a shared, systemic concern rather than a purely internal matter.

It is important to understand the boundaries of this control. As an ISO/IEC 27001:2022 Annex A reference control, 5.21 addresses one facet of an organization's information security management system, and its selection and depth of implementation are determined through the Statement of Applicability and risk assessment rather than being universally mandatory. Including this control does not guarantee freedom from supply chain compromise; it establishes processes to identify and address risk within the defined scope of the ISMS.

Who it's relevant to

GRC and Compliance Managers
Those responsible for building and maintaining an ISO 27001 ISMS need to decide whether and how to include Annex A 5.21 in their Statement of Applicability. Because inclusion and depth are driven by the organization's risk assessment rather than being inherently mandatory, these professionals must document the rationale for selection and configuration in a way that holds up during certification.
Procurement and Vendor Management Teams
Because this control concerns suppliers, partners, and service providers in the ICT supply chain, teams that source ICT products and services are central to implementing the defined processes and procedures. They help ensure that risks tied to third parties are identified and addressed rather than assumed to be safe.
Security Engineers and Architects
Those responsible for the technical integrity of ICT products and services benefit from processes that account for the global and distributed nature of the supply chain, helping ensure that risks introduced upstream are recognized and mitigated within their scope.
Certification Auditors and Assessors
Auditors evaluating an ISMS review how the organization has defined and implemented processes to manage ICT supply chain risk. The evidence expected can vary by scope, risk assessment, and certification body, so assessors examine whether the control's selection and configuration align with the organization's documented risk decisions.

Inside Managing Information Security in the ICT Supply Chain

Supplier Risk Assessment
The process of identifying and evaluating information security risks introduced by suppliers, subservice organizations, and downstream providers in the ICT supply chain. In ISO/IEC 27001 engagements, this typically feeds the risk assessment that informs control selection via the Statement of Applicability.
Supplier Agreements and Contractual Controls
Documented arrangements that define security requirements, responsibilities, and expectations for suppliers. In most engagements these cover access provisions, incident reporting, and the security obligations flowing through to the supplier's own sub-suppliers, depending on scope.
Annex A Supplier Relationship Controls
ISO/IEC 27001 Annex A includes reference controls addressing supplier relationships and ICT supply chain security. The specific control numbering and grouping depend on the edition; the 2022 revision reorganized Annex A into four themes, so the applicable version should be specified when citing controls.
Monitoring and Review of Supplier Services
Ongoing oversight of supplier performance and security posture, including review of any third-party assurance the supplier provides. This may include reviewing a supplier's SOC 2 report or ISO 27001 certificate as one input, though such evidence covers only the scope and period each document defines.
Statement of Applicability Linkage
Where supply chain controls are selected in an ISMS, their inclusion or exclusion is documented in the Statement of Applicability and justified by the risk assessment, consistent with the ISO/IEC 27001 clause 4 through 10 requirements.

Common questions

Answers to the questions practitioners most commonly ask about Managing Information Security in the ICT Supply Chain.

Does achieving SOC 2 or ISO 27001 mean my suppliers' security is automatically covered?
No. A SOC 2 report attests only to the controls and period covered within the service organization's defined scope, and an ISO 27001 certificate covers only the defined scope of that organization's ISMS. Neither outcome extends assurance to your suppliers automatically. Supply chain security typically requires you to assess each supplier's own controls, which may include requesting their SOC 2 reports or verifying their ISO 27001 certificates and reviewing the applicable scope.
Is there a single mandatory supply chain control I must implement to satisfy both frameworks?
Not in the sense of one universal control. Under ISO 27001, supplier-related requirements are addressed through Annex A reference controls that are selected via the Statement of Applicability and informed by risk assessment, so applicability depends on your scope. Under SOC 2, supply chain and vendor considerations are evaluated against the Trust Services Criteria relevant to your engagement, particularly the Security (Common Criteria) category. In most engagements the specifics depend on the auditor, certification body, scope, and your risk profile rather than a fixed mandate.
How should we identify which suppliers to prioritize for security review?
Prioritization typically follows a risk assessment that considers the sensitivity of data or systems each supplier can access, the criticality of the service they provide, and the potential impact of a supplier failure or compromise. In most programs, higher-risk suppliers receive more rigorous due diligence and more frequent review, while lower-risk relationships may be assessed more lightly. The exact tiering depends on your scope and risk appetite.
What evidence can we request from suppliers to support our own audit or certification?
Depending on scope, organizations commonly request a supplier's SOC 2 Type II report (which addresses both design and operating effectiveness of controls over a defined review period) or evidence of ISO 27001 certification along with the relevant scope statement. It is important to confirm that the supplier's report period, defined scope, and applicable criteria actually cover the services and data relevant to your relationship, since these documents attest only to what they explicitly include.
How do we handle a supplier that cannot provide a SOC 2 report or ISO 27001 certificate?
In many engagements, organizations rely on alternative assurance where formal reports or certificates are unavailable, such as completing security questionnaires, reviewing the supplier's policies, or conducting direct assessments. Contractual security requirements and monitoring provisions are also frequently used. The appropriate approach typically depends on the supplier's risk level and what your auditor or certification body considers sufficient for your defined scope.
How often should supplier security be reviewed after onboarding?
Review frequency generally reflects the supplier's assessed risk, with higher-risk relationships reviewed more often. Many programs perform periodic reassessments and also trigger reviews when significant changes occur, such as changes to the services provided, the data involved, or the supplier's own security posture. The specific cadence varies by scope and is set through your own risk-based decisions rather than a universal rule.

Common misconceptions

A supplier's SOC 2 report certifies that the supplier is secure, so no further oversight is needed.
A SOC 2 report is an attestation examination performed by a licensed CPA firm under SSAE 18; it is not a certification and it attests only to the controls and the period covered. It does not guarantee freedom from breaches, and reviewing it is typically one input among several rather than a complete substitute for ongoing supplier oversight.
If a supplier holds an ISO 27001 certificate, all of that supplier's services are covered.
An ISO/IEC 27001 certificate covers only the defined scope of the certified ISMS. Services, locations, or systems outside that scope are not covered, so the certificate's scope statement should be reviewed against the services actually being consumed.
Meeting ISO 27001 supply chain controls automatically satisfies SOC 2 supply chain expectations and vice versa.
Mapping between the two frameworks is possible but partial. ISO 27001 Annex A controls are distinct from the SOC 2 Trust Services Criteria, and satisfying supply chain requirements under one framework does not automatically satisfy the other; scope, criteria, and the assessing party differ.

Best practices

Base supplier security requirements on a documented risk assessment, and record the selection or exclusion of supply chain controls in the Statement of Applicability where an ISMS is in scope.
Define security obligations in supplier agreements, including access, incident reporting, and expectations that flow down to the supplier's own sub-suppliers, tailored to the scope of the relationship.
When relying on a supplier's SOC 2 report, review the report type and coverage period, and treat it as one assurance input rather than a guarantee; for a Type II, confirm the review period aligns with your reliance needs.
When relying on a supplier's ISO 27001 certificate, verify that the certified ISMS scope covers the specific services you consume, and note the certificate version where relevant.
Establish ongoing monitoring and periodic review of supplier services rather than relying on a single point-in-time assessment, since assurance evidence covers only defined scopes and periods.
Document the boundaries of what each piece of supplier assurance covers, and avoid assuming equivalence between frameworks when a supplier provides only one type of evidence.