The ultimate how to implement guide to ISO 27001 Annex A 5.21 Managing Information Security in the ICT Supply Chain.
Table of contents
- 1. Define the ICT Supply Chain Scope
- 2. Categorise Critical ICT Components
- 3. Implement Physical Hardware Chain of Custody
- 4. Perform Binary and Firmware Hash Verification
- 5. Enforce Hardened Remote Support Access
- 6. Verify Sub-Supplier (Fourth-Party) Disclosures
- 7. Define Explicit Security Requirements in RFPs
- 8. Implement Hardware Lifecycle and Disposal Logs
- 9. Mandate Vulnerability Disclosure Deadlines
- 10. Conduct Annual Physical Evidence Audits
1. Define the ICT Supply Chain Scope
Control Requirement: Identify and document all ICT products and services that impact the organisation’s security posture.
Required Implementation Step: Create a manual inventory of every hardware provider, software developer, and cloud service. Do not rely on “automated discovery” tools; walk through the server room and check the asset tags on switches, firewalls, and storage arrays to ensure every manufacturer is listed.
Minimum Requirement: A spreadsheet or internal database listing every ICT vendor and the specific component they provide.
2. Categorise Critical ICT Components
Control Requirement: Assess the criticality of ICT components based on their impact on confidentiality, integrity, and availability.
Required Implementation Step: Assign a risk level to each item in your inventory. Focus on “Single Points of Failure” (SPOF) where a vendor’s compromise would result in an immediate total system outage, such as your core router or identity provider.
Minimum Requirement: A documented risk assessment for all hardware and software that handles production data.
3. Implement Physical Hardware Chain of Custody
Control Requirement: Ensure ICT products are protected against tampering during transit and delivery.
Required Implementation Step: Establish a formal “Goods In” procedure. When a new server or network device arrives, an engineer must physically inspect the anti-tamper seals and photograph the serial numbers before the device is allowed into the secure zone.
Minimum Requirement: A signed log entry for every hardware delivery confirming the integrity of physical packaging.
DO IT YOURSELF
ISO 27001
All the templates, tools, support and knowledge you need to do it yourself.
4. Perform Binary and Firmware Hash Verification
Control Requirement: Verify the integrity of software and firmware updates before installation.
Required Implementation Step: Before applying any update, manually download the vendor’s provided SHA-256 hash. Run a checksum on the downloaded file in your local terminal to ensure the binary has not been intercepted or modified by a malicious middleman.
Minimum Requirement: Documentation in the Change Management log showing the verified hash for critical firmware updates.
5. Enforce Hardened Remote Support Access
Control Requirement: Control and monitor vendor access to internal ICT systems for support purposes.
Required Implementation Step: Disable all vendor VPNs by default in the firewall. Only enable access during an approved support window and ensure the vendor’s session is recorded via a terminal proxy or screen recording tool that you control locally.
Minimum Requirement: Firewall rules set to “Deny” for vendor access, requiring manual intervention for activation.
6. Verify Sub-Supplier (Fourth-Party) Disclosures
Control Requirement: Require ICT suppliers to disclose their own sub-contractors and monitor the risks involved.
Required Implementation Step: Demand a “Bill of Materials” (BOM) from your software vendors. You need to know which third-party libraries and data centres they are using, and you must document these dependencies in your internal risk register.
Minimum Requirement: A list of critical sub-processors for your top 5 most important ICT vendors.
7. Define Explicit Security Requirements in RFPs
Control Requirement: Incorporate information security requirements into the procurement process for ICT products.
Required Implementation Step: Add a mandatory “Security Appendix” to all Request for Proposals. Require vendors to prove they use Secure Development Lifecycle (SDLC) practices and provide evidence of independent penetration tests for their specific product version.
Minimum Requirement: A standard procurement template that includes mandatory security non-negotiables.
8. Implement Hardware Lifecycle and Disposal Logs
Control Requirement: Manage the security risks associated with the decommissioning and disposal of ICT equipment.
Required Implementation Step: When a disk or device reaches end-of-life, do not just put it in a bin. Record the serial number, physically shred the storage media on-site or through a certified provider, and keep the “Certificate of Destruction” in your local physical file.
Minimum Requirement: A disposal log cross-referenced with your asset inventory and certificates of destruction.
9. Mandate Vulnerability Disclosure Deadlines
Control Requirement: Ensure ICT suppliers notify the organisation of discovered vulnerabilities in their products.
Required Implementation Step: Update your contracts to include a “Critical Vulnerability Clause.” This must legally require the vendor to notify you within 24 hours of discovering a zero-day or high-severity vulnerability that affects your specific deployment.
Minimum Requirement: Contractual language specifying a maximum notification window for security defects.
10. Conduct Annual Physical Evidence Audits
Control Requirement: Regularly monitor and review ICT supply chain security performance.
Required Implementation Step: Once a year, pick a random ICT vendor and perform a “deep dive.” Ask for their latest SOC2 Type II report, but then manually verify that their physical security controls—like data centre access logs—actually match their claims.
Minimum Requirement: An annual audit report signed by the CISO covering ICT supply chain compliance.

