3.4 Organizational Controls: Supplier Relationships & Cloud Security (A.5.19–A.5.23)
Key Takeaways
- Control A.5.19 requires organizations to document policies and procedures to manage information security risks associated with supplier access to organizational assets.
- Control A.5.20 mandates that formal contracts with suppliers explicitly incorporate security requirements, SLAs, right to audit, and mandatory 24–48 hour incident notification timelines.
- Control A.5.21 targets ICT supply chain security, requiring risk management for software components, open-source libraries, code signing, and Software Bill of Materials (SBOM).
- Control A.5.22 dictates continuous monitoring, SLA reviews, SOC 2 / ISO 27001 audit report evaluations, and change management protocols for supplier services.
- Control A.5.23 is a dedicated 2022 control requiring processes for acquisition, use, cloud governance, Cloud Security Posture Management (CSPM), data sovereignty, and cloud exit strategies.
3.4 Organizational Controls: Supplier Relationships & Cloud Security (A.5.19–A.5.23)
Modern enterprise operating architectures depend heavily on external suppliers, managed service providers (MSPs), software supply chains, and cloud service providers (CSPs). Controls A.5.19 through A.5.23 provide the comprehensive risk management framework required to maintain information security boundaries across extended supply chains, vendor ecosystems, and multi-cloud environments.
Overview of Supplier & Cloud Controls (A.5.19 – A.5.23)
| Control ID | Control Name | ISO/IEC 27001:2022 Focus Area | Mandatory Implementation Deliverables |
|---|---|---|---|
| A.5.19 | Information security in supplier relationships | Processes and policies to manage security risks associated with supplier access to assets. | Supplier Risk Assessment Policy & Vendor Risk Tiering Matrix |
| A.5.20 | Addressing information security within supplier agreements | Contractual security requirements, SLAs, audit rights, and incident notification timelines. | Executed Vendor Agreements, DPAs & Security Appendices |
| A.5.21 | Managing information security in ICT supply chain | Risk management for hardware/software components, open-source code, and sub-vendors. | Software Bill of Materials (SBOM) & Code Signing Baseline |
| A.5.22 | Monitoring, review & change management of supplier services | Regular vendor performance monitoring, security audits, and managing vendor service changes. | SOC 2 Type II / ISO 27001 Review Logs & Vendor Audit Reports |
| A.5.23 | Information security for use of cloud services (New 2022) | Cloud governance, deployment, usage, configuration monitoring, and exit strategies. | Cloud Security Policy, CSPM Baseline & Cloud Exit Strategy |
Supplier Risk Lifecycle & Risk Tiering (A.5.19)
Control A.5.19 mandates that organizations establish formal processes to identify, assess, and manage security risks resulting from supplier relationships. Because third-party vendors vary widely in risk posture, the Lead Implementer must establish a Vendor Risk Tiering Framework based on asset criticality and access level:
- Tier 1 (Critical High Risk): Suppliers hosting or processing Confidential/Restricted data (e.g., cloud platform hosts, payment processors, managed security service providers - MSSPs). Require in-depth pre-contract due diligence, independent third-party audit reports (SOC 2 Type II, ISO/IEC 27001 certificates), annual penetration test evidence, continuous monitoring, and executive risk sign-off.
- Tier 2 (Moderate Risk): Vendors with limited access to non-sensitive operational systems or internal support facilities. Assessed via standardized questionnaires (e.g., CSA CAIQ, Shared Assessments SIG) and bi-annual compliance reviews.
- Tier 3 (Low Risk): Suppliers with zero logical access to organizational systems or data (e.g., office stationery suppliers). Standard contractual terms apply.
Essential Supplier Agreement Clauses (A.5.20)
Control A.5.20 mandates that information security requirements be formally documented and agreed upon in legal contracts prior to granting suppliers access to organizational assets. Essential contractual security clauses include:
- Data Protection & Regulatory Compliance: Explicit duties to protect data in compliance with relevant privacy regulations (GDPR, CCPA, HIPAA) and organizational security policies.
- Incident Notification SLA: Strict requirement for the supplier to notify the organization of any suspected or confirmed security breach within a binding timeframe (e.g., within 24 to 48 hours of discovery).
- Right to Audit & Assessment Rights: Contractual authority for the organization (or designated independent auditors) to inspect supplier controls, review vulnerability scans, and inspect annual SOC 2 Type II or ISO/IEC 27001 audit reports.
- Sub-Processor Approval: Vendor must obtain prior written authorization before delegating data processing to sub-contractors, ensuring sub-vendors adhere to identical security standards.
- Data Deletion & Exit Obligations: Enforceable obligations to return or cryptographically erase all organizational data upon contract termination, providing a certified Certificate of Destruction.
ICT Supply Chain Management & Software Supply Chain Security (A.5.21)
Control A.5.21 addresses complex risks inherent in the Information and Communications Technology (ICT) supply chain—including tampered hardware components, malicious software updates (such as the SolarWinds supply chain breach), and vulnerable open-source software dependencies.
+-------------------------------------------------------------------------+
| ICT SUPPLY CHAIN SECURITY ARCHITECTURE (A.5.21) |
+-------------------------------------------------------------------------+
1. Software Bill of Materials (SBOM): Mandate Machine-readable SBOMs |
(SPDX or CycloneDX formats) detailing all open-source libraries. |
2. Software Composition Analysis (SCA): Automated scanning of open- |
source dependencies against national vulnerability databases (CVEs). |
3. Cryptographic Code Signing: Require digital signatures on all |
software builds, firmware updates, and binary releases. |
4. Hardware Provenance: Verify component supply chain origin and authenticity |
to prevent counterfeit hardware implants. |
Monitoring, Review & Change Management of Supplier Services (A.5.22)
Supplier security risk management does not terminate once a contract is signed. Control A.5.22 mandates continuous monitoring and periodic review of supplier service delivery:
- Continuous Performance Auditing: Tracking supplier adherence to agreed Service Level Agreements (SLAs), uptime metrics, and security incident response performance.
- Third-Party Audit Review: Reviewing updated annual SOC 2 Type II reports, ISO/IEC 27001 certificates, and penetration testing summaries to verify that controls remain operational over time.
- Supplier Change Management: Establishing formal protocols to review and approve major changes in supplier services—such as data center relocations, major software architectural changes, or sub-processor substitutions—before changes take effect.
Deep-Dive: Cloud Security (A.5.23) — New in ISO 27001:2022
Control A.5.23 Information security for use of cloud services is a specialized control added to the 2022 edition of ISO/IEC 27001. It addresses the unique governance and technical challenges of operating in cloud environments under the Cloud Shared Responsibility Model.
The Cloud Shared Responsibility Model
+-------------------------------------------------------------------------+
| CLOUD SERVICE MODEL | CUSTOMER RESPONSIBILITY | CLOUD PROVIDER (CSP) |
+---------------------+----------------------------+----------------------+
| IaaS (e.g., AWS EC2,| OS, Middleware, Apps, Data,| Physical Data Center,|
| Azure VMs) | IAM, Firewall Rules, Patch | Hypervisor, Physical |
| | Encryption, CSPM Config | Network, Hardware |
+---------------------+----------------------------+----------------------+
| PaaS (e.g., Heroku, | Application Code, Data, | OS, Middleware, |
| AWS Lambda) | IAM, Database Schema | Runtime, Hypervisor, |
| | | Physical Infrastructure|
+---------------------+----------------------------+----------------------+
| SaaS (e.g., M365, | Data Classification, IAM, | Application Code, OS,|
| Salesforce) | Endpoint Devices, Access | Infrastructure, HW, |
| | Governance & MFA | Physical Data Center |
+-------------------------------------------------------------------------+
Core Lead Implementer Requirements for Control A.5.23:
- Cloud Security Policy & Shadow IT Prevention: Documenting formal approval workflows for acquiring cloud services, prohibiting unauthorized personnel from deploying cloud tenants (Shadow IT).
- Cloud Security Posture Management (CSPM): Deploying continuous automated monitoring tools to detect misconfigurations—such as publicly accessible S3 storage buckets, overly permissive security groups, or unencrypted cloud databases.
- Data Residency & Sovereignty: Verifying the geographic region and legal jurisdiction where cloud data is stored to ensure compliance with cross-border data transfer laws.
- Cloud Exit Strategy & Portability: Establishing documented, tested exit plans ensuring that organizational data and configurations can be extracted, migrated, or repatriated without data loss or vendor lock-in if a cloud provider terminates services or experiences financial failure.
Real-World Implementation Scenario:
Global Retail Inc. migrates its e-commerce infrastructure to AWS. The Lead Implementer establishes Control A.5.23 by enforcing a Cloud Security Policy prohibiting Shadow IT. The team deploys a CSPM tool (Wiz/AWS Security Hub) to continuously audit cloud configurations against CIS Benchmarks. Under Control A.5.21, custom microservices deployed to AWS ECS require automated Software Composition Analysis (SCA) to verify open-source libraries against an SBOM. Under Control A.5.20, AWS executed a GDPR Data Processing Addendum (DPA) incorporating a 24-hour breach notification SLA and documented exit data export procedures.
An enterprise contracts a third-party Cloud Service Provider (CSP) hosting its core Software-as-a-Service (SaaS) ERP application. Under Control A.5.23 and the Cloud Shared Responsibility Model, which security task remains the primary responsibility of the customer organization?
When drafting a contract with a key IT outsourcing provider, the Lead Implementer ensures the contract includes a clause granting the organization permission to perform annual security audits and inspect independent SOC 2 Type II reports. Which control is directly implemented by this contractual requirement?
Why does Control A.5.21 (Managing information security in the ICT supply chain) emphasize obtaining a machine-readable Software Bill of Materials (SBOM) for custom software applications?