ISO27001:2022 – A5.21 Managing information security in the ICT supply chain

Introduction to ISO 27001 – A5.21

Do not take ISO 27001 – A5.21 in isolation. It should be reviewed alongside:

The importance ISO27001 places on supplier relationships — especially in ICT — highlights just how critical this area is for information security.

What does the standard require?

The standard states:

“Processes and procedures shall be defined and implemented to manage the information security risks associated with the ICT products and services supply chain.” (ISO 27001 – A5.21)

ICT (Information and Communication Technology) products and services may include:

  • Network devices
  • Servers
  • Workstations
  • Mobile devices
  • Telecommunications and network services
  • Cloud services (see A5.23)
  • Instant messaging platforms (e.g. MS Teams)
  • Teleconferencing services (e.g. Zoom)
  • Managed Service Providers (MSPs)
  • Software development services
  • Penetration testing providers

Why is this required?

ICT vendors and services often have elevated access to your systems and data. Without oversight, they could introduce vulnerabilities — intentionally or not.

A prime example is the 2020 SolarWinds Orion attack. A vulnerability allowed attackers to gain access to thousands of customer networks, costing SolarWinds an estimated $40 million — with the broader global impact still unknown.

What the auditor is looking for

The auditor expects to see documented processes and procedures for managing ICT suppliers, including:

  • A supplier management process that includes ICT vendors
  • Risk assessments and due diligence for ICT providers
  • Signed agreements/contracts with clear terms
  • Evidence of supplier reviews and audits

What do you need to do?

  • Incorporate ICT-specific suppliers into your supplier management process (see A5.19)
  • Pay extra attention to those with elevated access — such as Managed Service Providers or software developers
  • Review their roles and risks individually — particularly around access, security responsibilities, and intellectual property ownership

Q & A

Do we need to document the process?

Yes — this control requires that “processes and procedures shall be defined.” You can incorporate this into your broader supplier management procedure developed under A5.19.

What specific requirements for ICT suppliers should we consider?

Extend the same basic principles you apply to other suppliers, but tailor them for the heightened risks ICT suppliers pose. For instance:

  • Ensure developer contracts cover intellectual property rights
  • Clarify whether custom-developed code can be reused for other clients
  • Define incident response obligations and security responsibilities in detail

Difficulty rating

We rate this control a 2 out of 5. It’s conceptually simple but may require more technical understanding when dealing with ICT providers (e.g. SOC, NOC, hosted infrastructure).

More questions?

ISO27001 controls are interconnected. For more support, review our FAQs or reach out directly.

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001”, available on Amazon, for practical implementation tips.

ISO 27001 – A5.21