A.5.20
    Organizational Controls

    Addressing information security within supplier agreements

    Relevant information security requirements should be established and agreed with each supplier based on the type of supplier relationship.

    Purpose

    To ensure suppliers understand and meet the organization's information security expectations.

    Implementation Guidance

    Include security clauses in all supplier contracts

    Define incident notification and response requirements

    Specify data handling and confidentiality requirements

    Include audit rights and compliance verification clauses

    Define termination and data return procedures

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.20 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.20 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.20 Addressing information security within supplier agreements. Built for compliance professionals.

    Try ISMS Copilot free