ISO/IEC 27000 Addressing Information Security Within Supplier Agreements, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to addressing information security within supplier agreements.
Assessment Step
1
Addressing Information Security Within Supplier Agreements (AddressingInformationSecurityWithinSupplierAgreements)
Has the organization established and agreed upon relevant information security requirements with each of its suppliers based on the type of supplier relationship?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Addressing Information Security Within Supplier Agreements
Relevant information security requirements shall be established and agreed with each supplier based on the type of supplier relationship.
Citations
27001
Annex A, Control 5.20
27002
Section 5.20
|