A5.22 Monitoring, review and change management of supplier services
5 min read
Managing information security in supplier relationships is essential for safeguarding sensitive data shared between an organization and its third-party suppliers. Suppliers often have access to business-critical data, systems, and processes, and any vulnerabilities within these relationships can lead to data breaches, operational disruptions, and compliance violations.
ISO 27001 A5.22 Monitoring, review and change management of supplier services emphasizes the need for organizations to establish and manage proper controls when interacting with suppliers to ensure the security of sensitive information. This control ensures that third-party suppliers adhere to the same information security standards and practices as the organization itself.
Why is this important? #
- Third-party risk: Suppliers can be a potential entry point for cyberattacks or data leaks.
- Compliance: Organizations are legally required to ensure their suppliers follow adequate data protection standards.
- Data protection: Sensitive organizational data shared with suppliers must be protected throughout its lifecycle.
Implementation Guide #
Step 1: Define Information Security Requirements for Suppliers
Before entering into any supplier agreement, clearly define the information security requirements that the supplier must meet. These requirements should be included in contracts and agreements.
What to include:
- Data protection: Specify how suppliers should handle, store, and process sensitive data.
- Security controls: Define the necessary security measures suppliers must have in place, such as encryption, firewalls, and access control.
- Audit rights: Include the right to audit the supplier’s security practices and access related information.
Recommended Tools:
- Supplier Risk Management Tools: RiskWatch, OneTrust, and Prevalent can be used to assess and monitor supplier risks.
Step 2: Conduct Due Diligence Before Engaging Suppliers
Perform a thorough risk assessment before selecting or onboarding a supplier. This helps identify potential risks regarding data protection, regulatory compliance, and operational impact.
Key steps in due diligence:
- Assess the security posture of potential suppliers (e.g., security certifications like ISO 27001, SOC 2).
- Review supplier policies on data handling, security, and breach response.
- Conduct site visits or interviews with supplier security teams to understand their controls.
Recommended Tools:
- Third-Party Risk Assessment Tools: BitSight, SecurityScorecard, and CyberGRX help assess the security health of suppliers.
Step 3: Incorporate Information Security Clauses into Contracts
Information security clauses should be part of any supplier contract or service level agreement (SLA). These clauses should outline the responsibilities and obligations of the supplier regarding data protection, incident response, and security monitoring.
Key contract clauses:
- Data security measures: What the supplier will do to protect the data, including encryption and regular vulnerability testing.
- Incident reporting: The supplier’s obligation to notify the organization immediately in case of a data breach or security incident.
- Right to audit: The organization’s right to conduct security audits on the supplier’s systems, processes, and controls.
Recommended Tools:
- Contract Management Software: DocuSign, Concord, or ContractWorks can be used to streamline contract creation and ensure that security clauses are included.
Step 4: Monitor Supplier Security Continuously
Ongoing monitoring is essential to ensure that the supplier is continuously meeting the required security standards. Monitoring should include regular security assessments, audits, and performance reviews.
What to do:
- Perform regular audits of the supplier’s security practices, access controls, and data handling.
- Request security reports or penetration test results from suppliers regularly.
- Use tools to track supplier performance and measure compliance with the security contract.
Recommended Tools:
- Supplier Monitoring Tools: SecurityScorecard, RiskRecon, and BitSight can monitor and score the security of your suppliers over time.
What not to do:
- Neglect monitoring: A one-time audit is not enough; continuous monitoring is critical.
- Assume compliance: Just because a supplier is compliant at the start doesn’t mean they always will be. Regular checks are necessary.
Step 5: Ensure Proper Incident Response and Contingency Planning
It’s vital that both your organization and suppliers have established incident response plans in case of a security breach or data loss. These plans should align with each other to ensure a coordinated response.
Key actions:
- Develop joint incident response procedures with suppliers to ensure quick detection and resolution.
- Test the response plan regularly with suppliers to ensure it works during a real incident.
Recommended Tools:
- Incident Response Tools: PagerDuty, Splunk, and IBM Resilient can help manage and track incidents across the supply chain.
Step 6: Terminate Supplier Contracts Securely
When a supplier relationship ends, ensure that all sensitive data is securely returned or destroyed, and access to systems or networks is promptly revoked.
Actions:
- Ensure data is wiped: Make sure any data shared with the supplier is either returned or securely deleted.
- Revoke all access rights: Ensure that any accounts, credentials, or VPN access are immediately revoked.
Recommended Tools:
- Data Sanitization Tools: Blancco, Certus, and DBAN can help securely erase data from suppliers’ systems.
Templates #
- Supplier Risk Assessment Template
- Supplier Security Audit Checklist
- Supplier Information Security Agreement Template
- Incident Response Plan Template
Example Scenario #
A financial institution contracts a third-party vendor to manage customer account data. The vendor experiences a data breach due to weak access controls, and customer information is compromised.
Solution:
The financial institution had a robust supplier information security policy that required encryption for all customer data. The vendor did not follow these protocols, and as a result, the organization was able to enforce breach penalties and mitigate the risk by severing the relationship with the vendor.
How to Comply with ISO 27001 A.5.19 #
To comply, organizations should:
- Define security expectations with all suppliers through contracts.
- Regularly monitor supplier performance to ensure they are meeting security standards.
- Perform due diligence and security assessments before onboarding suppliers.
- Have a clear incident response and data handling procedure in place with suppliers.
How to Pass an Audit #
Key Documents to Prepare:
- Supplier Risk Assessment Reports
- Supplier Security Audit Logs
- Supplier Contracts with Security Clauses
What the Auditor Will Check: #
- Does the organization have a formal process for selecting and assessing suppliers based on security risks?
- Are security controls outlined in supplier contracts, and are they being adhered to?
- Are security audits conducted regularly on supplier systems?
Top 3 Mistakes Organizations Make #
- Lack of supplier monitoring: Organizations fail to continuously evaluate the security posture of suppliers after the initial contract.
- Ignoring due diligence: Rushing into contracts without fully assessing the security practices of potential suppliers.
- Not enforcing contract clauses: Failing to hold suppliers accountable for non-compliance with security agreements.
ISO 27001 Information Security in Supplier Relationships FAQ #
Q1: Should all suppliers be assessed for information security risks?
Yes, all suppliers who handle sensitive or critical data should be assessed for information security risks.
Q2: How often should I monitor my suppliers?
Monitoring should be continuous, with quarterly or semi-annual audits to ensure compliance with security requirements.
Q3: Can I terminate a supplier if they fail to meet security standards?
Yes, if a supplier fails to meet agreed-upon security standards, termination clauses should be enforced as per the contract.
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.5.19 Information Security in Supplier Relationships | Preventive, Risk-Based, Operational |
| Purpose | Ensure that suppliers maintain adequate information security controls |
| Applicability | All departments involved in supplier management and contract negotiations |
| ISO 27001 Domains | Supplier Relationship Management, Risk Management, IT Security |
Ensuring that your supplier relationships adhere to the highest standards of information security is vital for protecting sensitive data and complying with legal and regulatory frameworks. Continuous monitoring, well-defined contracts, and robust due diligence processes will help mitigate risks from suppliers.
Action Step: Review your supplier contracts and conduct a security assessment of your key suppliers today!