ISO/IEC 27000 Information Security in Supplier Relationships, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to information security in supplier relationships.
Assessment Step
1
Information Security in Supplier Relationships (InformationSecurityinSupplierRelationships)
Has the organization defined and implemented processes and procedures to manage the information security risks associated with the use of supplier products or services?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Information Security in Supplier Relationships
Processes and procedures shall be defined and implemented to manage the information security risks associated with the use of supplier's products or services.
Citations
27001
Annex A, Control 5.19
27002
Section 5.19
|