Back to all 93 controls
    Annex A 5.21
    Organizational

    A.5.21 Managing information security in the ICT supply chain

    ICT supply chain risks are managed.

    What good looks like

    Visibility of sub-processors, software components (SBOM), and propagation of security requirements.

    Evidence an auditor will ask for

    Sub-processor list, SBOMs, supplier audit reports.

    Document template for this control

    The Third Party Security Policy template gives you auditor-ready wording that fulfils Annex A 5.21. Preview the full document before you download the editable version.