Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.21

Managing Information Security in the ICT Supply Chain: A Practical Implementation Guide

Look beyond direct suppliers to technology components, dependencies and downstream providers.

This control addresses information security risks within the ICT product and service supply chain, including components and subcontractors.

Practical interpretation: The direct vendor may not control every dependency. Organizations need visibility and risk-based assurance for software, hardware, cloud, updates and downstream service chains.

What should the control achieve?

  • Critical ICT dependencies are understood.
  • Supply-chain requirements flow through direct suppliers.
  • Authenticity and integrity of components and updates are considered.
  • Concentration, substitution and end-of-life risks are managed.

Step-by-step implementation

1

Map the chain

Identify direct providers, critical subprocessors, components, update channels and geographic dependencies.

2

Assess supply-chain threats

Consider tampering, counterfeit components, compromised updates, concentration and unsupported products.

3

Set requirements

Require supplier governance, component provenance, vulnerability disclosure and downstream controls.

4

Verify delivery integrity

Use trusted sources, signatures, hashes, secure transport and acceptance checks.

5

Monitor change

Track ownership, subprocessor, component, vulnerability and end-of-life changes.

6

Prepare alternatives

Define resilience, replacement and exit plans for critical dependencies.

What this could look like in practice

A software company maintains component inventories for its product, monitors upstream security advisories and verifies signed build artifacts. Critical cloud subprocessors are contractually disclosed and material changes trigger review.

ActivityPractical implementationEvidence
Software componentSBOM and dependency scanning reveal upstream exposure.Component inventory
UpdateSignature and source are verified before deployment.Verification log
Subprocessor changeSupplier notification triggers risk review.Change assessment

Implementation evidence

  • ICT supply-chain policy
  • Dependency maps
  • SBOMs or component lists
  • Provenance requirements
  • Update-verification records
  • Subprocessor inventories
  • End-of-life tracking
  • Alternative plans

Useful metrics

  • Critical components with known provenance
  • Unsupported components
  • Unreviewed subprocessor changes
  • Supply-chain findings overdue

Common mistakes

  • Assessing only the direct supplier.
  • Ignoring open-source and embedded components.
  • Trusting updates solely because they arrive automatically.
  • No visibility of end-of-life dates.
  • Concentrating critical services without an exit option.

Questions an auditor may ask

  • How do you identify downstream dependencies?
  • How is update integrity verified?
  • Show response to an upstream vulnerability.
  • What alternatives exist for critical concentration?
Implementation test: Choose a critical technology service and map the direct supplier, subprocessors, key components, update path and replacement options.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.