- ISO 27001
- Annex A
ISO 27001 Annex A 5.21: Managing information security in the ICT supply chain
Updated 5 min read
Your suppliers have suppliers. The SaaS tool that holds your customer data runs on someone’s cloud, sends email through someone else, and is built from open-source components nobody at the vendor wrote. Annex A 5.21 asks you to manage the security risk that comes with that chain for ICT products and services — without pretending you can audit all of it yourself.
This page covers what the control requires, a proportionate way to meet it, what auditors look for and an evidence checklist. For the five supplier controls together, see ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence.
What Annex A 5.21 requires
The control, paraphrased: processes and procedures should be defined and implemented to manage the information security risks associated with the ICT products and services supply chain. Its full title is Managing information security in the information and communication technology (ICT) supply chain, and it replaced A.15.1.3 in the 2013 edition.
The ISO/IEC 27002:2022 guidance, summarised, expects you to:
- define security requirements for the ICT products and services you acquire;
- require ICT service suppliers to propagate your requirements through their supply chain when they subcontract, and product suppliers to propagate appropriate security practices;
- identify the components that are critical to the product or service, and obtain assurance that they and their origin can be traced;
- monitor and validate that delivered ICT products and services work as expected, without unexpected or unwanted features;
- agree rules for sharing information about the supply chain and potential issues;
- manage lifecycle risks, such as components that become unavailable or unsupported because a supplier stops making them or goes out of business.
The ISO/IEC 27036 series (Cybersecurity — Supplier relationships) goes deeper; part 3 covers hardware, software and services supply chain security.
A proportionate implementation
For most organisations buying ICT services rather than building hardware:
- Three questions in the questionnaire for critical and high-tier ICT suppliers: who are your sub-processors or critical sub-suppliers for this service, how do you assess them, and how much notice do we get before one changes? Vendor risk assessment questionnaire: what to ask, and how to score the answers shows where they fit.
- A flow-down clause in agreements with those suppliers, requiring them to impose equivalent security obligations on their subcontractors. This links 5.21 to ISO 27001 Annex A 5.20: Addressing information security within supplier agreements.
- A dependency inventory for software you build or deploy: the components, their versions and whether they are still supported, with a patching process. That evidence also serves controls such as 8.8 (Management of technical vulnerabilities).
- A concentration view: which fourth parties sit behind several of your critical suppliers at once. One cloud region or one email provider behind half your stack is a risk no single supplier assessment will show.
For vendors that use AI models from another provider, that provider is a fourth party too; AI vendor due diligence: a checklist for vendors that use AI on your data lists the questions to ask.
What certification auditors look for
- For a sampled ICT supplier: do you know its critical sub-suppliers, and how did you find out?
- Is there a flow-down requirement in the agreement?
- Has a sub-supplier change been notified in the period, and what did you do with it?
- For software you build: how do you know what components you ship and use?
Evidence checklist for Annex A 5.21
- Security requirements for ICT products and services, in the supplier procedure
- Sub-processor or sub-supplier lists for critical and high-tier ICT suppliers
- Questionnaire answers on how those suppliers assess their own suppliers
- Flow-down clauses in the agreements of sampled ICT suppliers
- Record of a sub-supplier change being reviewed, with the decision
- Dependency inventory or SBOM for software you develop, with support status
- Lifecycle and end-of-support tracking for critical ICT components
Related controls
- ISO 27001 Annex A 5.19: Information security in supplier relationships — the overall supplier process.
- ISO 27001 Annex A 5.22: Monitoring, review and change management of supplier services — reviewing a sub-supplier change when it happens.
- ISO 27001 Annex A 5.23: Information security for use of cloud services — cloud services, where most ICT supply chains now run.
Also relevant: 8.30 (Outsourced development), when the supplier develops software for you, and the glossary entries on fourth-party and Nth-party risk.
Frequently asked questions
- What is ISO 27001 Annex A 5.21?
- Annex A 5.21, Managing information security in the information and communication technology (ICT) supply chain, requires processes and procedures to manage the information security risks associated with the ICT products and services supply chain. It replaced A.15.1.3 of ISO/IEC 27001:2013.
- Do I have to assess my suppliers' suppliers under 5.21?
- Not directly. The control expects you to require your ICT suppliers to pass your security requirements down their own chain, to know which of their suppliers are critical to the service you receive, and to be told about changes. You assess your supplier's management of its suppliers, not every fourth party yourself.
- What is the difference between 5.19 and 5.21?
- 5.19 covers supplier relationships in general, including non-ICT suppliers. 5.21 adds requirements specific to ICT products and services: propagating requirements through the supply chain, tracing critical components and their origin, validating that delivered products work as expected, and managing component lifecycle risks such as end of support.
- Is a software bill of materials (SBOM) required for ISO 27001?
- No. ISO/IEC 27001:2022 does not mention SBOMs. An SBOM is one practical way to meet the 5.21 guidance on knowing the components in the ICT products you rely on and their origin, especially for software you build or ship, but a dependency inventory and supplier attestations can also do the job.
Related guides
- ISO 27001
- Audit
ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence
The five supplier controls in the 2022 edition, what each demands, and the records that satisfy them.
11 min read
- ISO 27001
- Annex A
ISO 27001 Annex A 5.19: Information security in supplier relationships
The control that asks for a supplier security process: types of supplier, tiers, requirements, and the records that prove it ran.
5 min read
- ISO 27001
- Annex A
ISO 27001 Annex A 5.20: Addressing information security within supplier agreements
Which security requirements belong in the supplier contract, how to handle vendors on their own paper, and the gap log auditors ask for.
5 min read