A.5.22
    Organizational Controls

    Monitoring, review and change management of supplier services

    The organization should regularly monitor, review, evaluate and manage change in supplier information security practices and service delivery.

    Purpose

    To ensure suppliers continue to meet security requirements throughout the relationship.

    Implementation Guidance

    Establish KPIs and SLAs for supplier security performance

    Conduct regular security reviews of supplier services

    Require notification of significant changes to supplier services

    Implement change management processes for supplier changes

    Maintain evidence of supplier security assessments

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.22 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.22 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.22 Monitoring, review and change management of supplier services. Built for compliance professionals.

    Try ISMS Copilot free