A.5.21
    Organizational Controls

    Managing information security in the ICT supply chain

    Processes and procedures should be defined and implemented to manage the information security risks associated with the ICT products and services supply chain.

    Purpose

    To address information security risks within the ICT supply chain.

    Implementation Guidance

    Assess security risks in the supply chain

    Verify the security of ICT products and services

    Monitor supplier security practices continuously

    Implement secure development practices for custom software

    Maintain visibility into the supply chain

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.21 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.21 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.21 Managing information security in the ICT supply chain. Built for compliance professionals.

    Try ISMS Copilot free