Back to all 93 controls
Annex A 5.21
Organizational
A.5.21 Managing information security in the ICT supply chain
ICT supply chain risks are managed.
What good looks like
Visibility of sub-processors, software components (SBOM), and propagation of security requirements.
Evidence an auditor will ask for
Sub-processor list, SBOMs, supplier audit reports.
Document template for this control
The Third Party Security Policy template gives you auditor-ready wording that fulfils Annex A 5.21. Preview the full document before you download the editable version.
