ISO/IEC 27000 Monitoring, Review and Change Management of Supplier Services, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to monitoring, review and change management of supplier services.
Assessment Step
1
Monitoring, Review and Change Management of Supplier Services (MonitoringReviewandChangeManagementofSupplierServices)
Does the organization regularly monitor, review, evaluate, and manage changes in supplier information security practices and service delivery?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Monitoring, Review and Change Management of Supplier Services
The organization shall regularly monitor, review, evaluate and manage change in supplier information security practices and service delivery.
Citations
27001
Annex A, Control 5.22
27002
Section 5.22
|