A.5.19
    Organizational Controls

    Information security in supplier relationships

    Processes and procedures should be defined and implemented to manage the information security risks associated with the use of supplier's products or services.

    Purpose

    To ensure protection of the organization's information that is accessible by suppliers.

    Implementation Guidance

    Conduct security assessments of suppliers before engagement

    Include information security requirements in supplier contracts

    Define and agree on security controls with suppliers

    Monitor supplier compliance with security requirements

    Establish incident response procedures for supplier-related incidents

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.5.19 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.5.19 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.5.19 Information security in supplier relationships. Built for compliance professionals.

    Try ISMS Copilot free