Managing Information Security in the ICT Supply Chain
This is an ISO/IEC 27001 reference control that addresses the security risks that come from the suppliers, partners, and service providers who help produce or deliver an organization's information and communications technology (ICT) products and services. Because ICT products and services move through a global and distributed chain of vendors, this control asks organizations to define processes that identify and reduce the security risks introduced along that chain. In practice, it helps ensure that risks tied to third parties in the ICT supply chain are recognized and managed rather than assumed to be safe.
In the ISO/IEC 27001:2022 revision, this control appears as Annex A 5.21, one of the reference controls listed in Annex A that organizations may select through their Statement of Applicability and risk assessment rather than a clause 4-10 ISMS requirement that is inherently mandatory. It calls for processes and procedures to be defined and implemented to manage information security risks associated with the ICT products and services supply chain, with the objective of ensuring that risks associated with suppliers, partners, and service providers are identified and addressed. This aligns conceptually with the broader discipline of ICT supply chain risk management, described as the process of identifying, assessing, and mitigating risks associated with the global and distributed nature of ICT product and service supply chains. The precise applicability, implementation depth, and evidence expected depend on scope, the organization's risk assessment, and the certification body; as an Annex A reference control, its selection and configuration vary by engagement, and inclusion is determined via the Statement of Applicability rather than universally required.
Why it matters
Modern ICT products and services rarely originate from a single source. As described in the evidence, the ICT supply chain is the sequence of actions that transform raw resources into products and services such as computer hardware and software, and this chain is global and distributed by nature. That distribution means an organization's security posture depends not only on its own controls but also on the suppliers, partners, and service providers embedded throughout the chain. A weakness introduced by any of those third parties can propagate downstream, which is why Annex A 5.21 asks organizations to treat supply chain risk as something to be actively identified and managed rather than assumed to be safe.
The discipline this control supports, ICT supply chain risk management, is defined as the process of identifying, assessing, and mitigating the risks associated with the global and distributed nature of ICT product and service supply chains. Recognition of these risks at a national level is reflected in public-private efforts, such as the CISA-associated partnership charged with identifying and developing consensus risk management strategies to enhance global ICT supply chain security. This underscores that supply chain security is treated as a shared, systemic concern rather than a purely internal matter.
It is important to understand the boundaries of this control. As an ISO/IEC 27001:2022 Annex A reference control, 5.21 addresses one facet of an organization's information security management system, and its selection and depth of implementation are determined through the Statement of Applicability and risk assessment rather than being universally mandatory. Including this control does not guarantee freedom from supply chain compromise; it establishes processes to identify and address risk within the defined scope of the ISMS.
Who it's relevant to
Inside Managing Information Security in the ICT Supply Chain
Common questions
Answers to the questions practitioners most commonly ask about Managing Information Security in the ICT Supply Chain.