ISO/IEC 27000 Managing Information Security in the ICT Supply Chain, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to managing information security in the ict supply chain.
Assessment Step
1
Managing Information Security in the ICT Supply Chain (ManagingInformationSecurityintheICTSupplyChain)
Has the organization defined and implemented processes and procedures to manage information security risks in its ICT products and services supply chain?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Managing Information Security in the ICT Supply Chain
Processes and procedures shall be defined and implemented to manage the information security risks associated with the ICT products and services supply chain.
Citations
27001
Annex A, Control 5.21
27002
Section 5.21
|