isms.coach
← All controls

A.5.21 · Organizational

Managing information security in the ICT supply chain

Why it matters

A compromised upstream dependency (a library, a hosting provider) can compromise you without any mistake on your part.

How a self-led small team implements it

List your critical infrastructure dependencies and note each one's security posture in one line — depth follows over time.

What auditors expect to see

Supply chain risk register or dependency list.

Track A.5.21 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.

Start your ISMS

More organizational controls