A5.20 Addressing information security within supplier agreements
5 min read
When organizations collaborate with suppliers, vendors, or third parties, sensitive data and critical systems may be shared or accessed externally. “A5.20 Addressing information security within supplier agreements” ensures that information security requirements are clearly defined and enforced within supplier agreements to prevent unauthorized access, data breaches, or non-compliance with security policies.
Failing to establish strong security clauses in supplier contracts can expose an organization to:
- Data leaks from weak security practices.
- Regulatory fines for non-compliance (e.g., GDPR, ISO 27001).
- Supply chain attacks, where attackers exploit a supplier’s weak security to infiltrate the organization.
Implementation Guide #
Step 1: Define Security Requirements in Contracts
All supplier agreements should explicitly define security expectations to ensure suppliers protect data, systems, and services appropriately. These requirements should align with ISO 27001, GDPR, NIST, or other relevant standards.
What to Include in Supplier Contracts:
- Data Protection Requirements – Define how suppliers must handle, process, and store data.
- Access Control Policies – Specify who can access what data and under what conditions.
- Encryption Requirements – Ensure sensitive data is encrypted both in transit and at rest.
- Incident Reporting – Define the timeframe and process for reporting security incidents.
- Audit & Compliance Rights – Allow periodic security audits to assess compliance.
- Termination & Exit Strategy – Ensure proper data deletion and access revocation upon contract termination.
Recommended Tools:
- Contract Management: DocuSign, Ironclad, or ContractWorks
- Security Policy Frameworks: NIST CSF, ISO 27001, GDPR compliance tools
Step 2: Conduct Supplier Risk Assessments Before Contracting
Before finalizing agreements, organizations should assess a supplier’s security posture, policies, and compliance status.
How to Assess Suppliers:
- Security Certifications – Verify if the supplier follows ISO 27001, SOC 2, or NIST 800-53.
- Risk Assessment Reports – Request security audits, penetration testing results, or compliance reports.
- Data Handling Practices – Evaluate how suppliers store, transmit, and dispose of data.
- Access Control Reviews – Identify how suppliers manage privileged access and authentication.
- Incident Response Plan – Ensure the supplier has a defined incident management process.
Recommended Tools:
- Third-Party Risk Assessment: BitSight, SecurityScorecard, Prevalent
- Compliance Monitoring: OneTrust, TrustArc, Compliance.ai
Step 3: Enforce Compliance Through Periodic Audits
Even after signing contracts, suppliers should be continuously monitored to ensure compliance with security clauses.
What to Do:
- Conduct regular security audits (quarterly or annually).
- Require suppliers to submit compliance reports and penetration test results.
- Perform on-site inspections or virtual assessments to verify security measures.
- Use real-time monitoring tools to track supplier risks and vulnerabilities.
Recommended Tools:
- Supplier Audit & Compliance: LogicGate, Archer, Resolver
- Continuous Security Monitoring: RiskRecon, UpGuard, CyberGRX
Step 4: Establish Clear Incident Response & Breach Notification Protocols
In case of a data breach, suppliers must be required to immediately report incidents and coordinate with the organization’s security team.
Incident Response Clauses to Include in Contracts:
- Breach Notification – Define the timeframe for reporting incidents (e.g., within 24 hours).
- Remediation Plan – Require suppliers to provide an action plan to mitigate breaches.
- Forensic Investigation – Suppliers should cooperate in forensic analysis to determine root causes.
- Liability & Penalties – Define financial penalties or contract termination for security failures.
Recommended Tools:
- Incident Response Platforms: IBM Resilient, Splunk Phantom, Rapid7 InsightIDR
- Threat Intelligence & Monitoring: Palo Alto Cortex XSOAR, Microsoft Sentinel
Step 5: Secure Data Transfers & Termination Procedures
When a supplier contract ends, ensure proper data return, deletion, or secure transfer to prevent unauthorized retention or misuse.
Key Requirements for Secure Data Handling:
- Data Retention Policy – Define how long suppliers can store data before secure deletion.
- Secure Data Transfer – Use encryption (TLS, AES-256) for transferring sensitive information.
- Data Destruction Requirements – Ensure suppliers use certified data wiping tools upon contract termination.
- Access Revocation – Immediately revoke system, database, and API access when the agreement ends.
Recommended Tools:
- Data Erasure & Sanitization: Blancco, Certus, DBAN
- Secure File Transfer: AWS S3 Transfer, Azure Secure FTP, OpenText Secure MFT
Templates #
- Supplier Security Risk Assessment Template
- Information Security Clauses for Contracts
- Supplier Security Audit Checklist
- Incident Response Agreement with Suppliers
Example Scenario #
A software development company contracts a third-party cloud provider for data storage. The agreement fails to include a clause for security audits. Later, the cloud provider suffers a data breach, exposing customer information.
What Went Wrong?
- No right to audit clause was included in the contract.
- No breach notification timeframe, leading to delayed response.
- No data handling requirements, leaving sensitive data vulnerable.
Solution:
The company updates all supplier agreements to include:
- Security audit rights every 6 months.
- Breach reporting within 24 hours of discovery.
- Mandatory encryption for all stored customer data.
How to Comply with ISO 27001 A.5.20 #
To pass an ISO 27001 audit, organizations must:
- Ensure all supplier contracts include specific security clauses.
- Conduct regular risk assessments and supplier security reviews.
- Monitor supplier compliance with security policies continuously.
- Require incident response plans for third-party security breaches.
How to Pass an Audit #
Key Documents to Prepare:
- Supplier Security Policy
- Third-Party Risk Assessment Reports
- Supplier Contracts with Security Clauses
- Incident Response Agreements
What the Auditor Will Check:
- Are security requirements clearly defined in contracts?
- Are suppliers regularly assessed for compliance?
- Does the organization monitor supplier security continuously?
- Is there a clear response plan for supplier-related security incidents?
Top 3 Mistakes Organizations Make #
- Vague contract terms – Security clauses are not clearly defined.
- No supplier monitoring – Organizations fail to check supplier compliance regularly.
- Lack of breach response planning – No clear protocol for responding to supplier security incidents.
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.5.20 Addressing Information Security Within Supplier Agreements | Preventive, Risk-Based, Operational |
| Purpose | Ensure supplier agreements include security controls |
| Applicability | Procurement, Legal, IT Security, Compliance |
| ISO 27001 Domains | Supplier Relationship Management, Risk Management, IT Security |
Strong supplier agreements are a critical part of an organization’s security posture. Ensuring that all contracts include well-defined security expectations will help prevent data breaches, maintain compliance, and mitigate risks.