ISO27002: 2022 Clause 5.22 Monitor, review and change management of supplier services
In this article I lay bare ISO27001 Annex A 5.22 / ISO27002: 2022 Clause 5.22 Monitor, review and change management of supplier services.
A beginners guide, exposing the insider trade secrets, giving you the templates that will save you hours of your life and showing you exactly what you need to do to satisfy it for ISO27001 certification. We show you exactly what changed in the ISO27001:2022 update. I am Stuart Barker the ISO27001 Ninja and this is ISO27001 Annex A 5.22
Table of contents
- ISO27002: 2022 Clause 5.22 Monitor, review and change management of supplier services
- What is ISO27001 Annex A 5.22 Monitor, review and change management of supplier services?
- ISO27001 Annex A 5.22 Definition
- In plain English?
- ISO27001 Annex A 5.22 Implementation Guide
- ISO27001 Annex A 5.22 Templates
- How to comply with ISO27001 Annex A 5.22
- How to pass an audit of ISO27001 Annex A 5.22
- What will an audit check?
- Top 3 Annex ISO27001 A 5.22 Mistakes People Make
- Why is ISO27001 Annex A 5.22 Important?
- ISO27001 Annex A 5.22 FAQ
- Matrix of controls and attribute values
- See Also
What is ISO27001 Annex A 5.22 Monitor, review and change management of supplier services?
ISO27001 Annex A 5.22 Monitor, review and change management of supplier services is an ISO27002: 2022 control that requires an organisation to maintain an agreed level of service and information security in line with legal agreements.
ISO27001 Annex A 5.22 Definition
The ISO27001 standard defines Annex A 5.22 Monitor, review and change management of supplier services as:
The organisation should regularly monitor, review, evaluate and manage change in supplier information security practices and service delivery.ISO27001 Annex A 5.22
In plain English?
Ensure the confidentiality, integrity and availability of your suppliers, their products and their services through monitoring and review.
ISO27001 Annex A 5.22 Implementation Guide
As with all the clauses that relate to supplier management we are looking to assign the responsibility to a person or a team with the skills and resources to be able to track that requirements are being met and where not, they are being addressed.
In basic terms it is about making sure that the terms and conditions in legal agreements that relate to information security are being met. It is about managing issues, problems and incidents as the occur and if changes are needed to suppliers that those changes do not adversely impact the business.
You are going to:
- Those service performance levels are going to be monitored, most likely via reports or metrics or dashboards.
- Check and respond to changes made by suppliers such as updates, changes to process, changes to controls
- Where supplier services change to monitor and respond to those
- Keep your eye on the terms and conditions of the agreements and that they are followed
- Ensure those pesky suppliers are evaluated and maintain adequate security
It isn’t really that hard although you can over complicate it very easily. Have agreements in place, make sure they are followed, check them and respond when things go wrong.
We are not teaching people how to do supplier management or change it. What is here is common sense.
ISO27001 Annex A 5.22 Templates
You can save months of effort with these templates that take 25 years of experience and distill it in a pack of prewritten best practice awesomeness.
Do it yourself
SAVE over £10,000
How to comply with ISO27001 Annex A 5.22
To comply with ISO27001 Annex A 5.22 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to
- Implement a topic specific policy
- Implement a supplier management process
- Include in your supplier management process supplier acquisition and supplier transfer
- Implement a third party supplier register
- Have agreements with all suppliers that cover information security requirements
- Have information security assurances for critical suppliers as a minimum and ideally all relevant suppliers
- Monitor those suppliers
- Respond to adverse incidents in a structured way
How to pass an audit of ISO27001 Annex A 5.22
To pass an audit of ISO27001 Annex A 5.22 Monitor, review and change management of supplier services you are going to make sure that you have followed the steps above in how to comply.
You are going to do that by first conducting an internal audit, following the How to Conduct an ISO27001 Internal Audit Guide.
What will an audit check?
The audit is going to check a number of areas. Lets go through the most common
#1 That you have a supplier agreements in place
The auditor is going to check that you have agreements in place with suppliers that cover the information security requriements. It will check that those agreements are in date and cover the products and / or services acquired.
#2 That you have an ISO27001 Supplier Register
You will need an ISO27001 Supplier Register to record and manage your suppliers. Make sure it is up to date and reflects your reality.
They are going to look at audit trails and all your documentation and see that is classified and labelled. All the documents that you show them, as a minimum if they are confidential should be labelled as such. Is the document up to date. Has it been reviewed in the last 12 months. Does the version control match.
Top 3 Annex ISO27001 A 5.22 Mistakes People Make
The top 3 Mistakes People Make For ISO27001 Annex A 5.22 are
#1 You have do not monitor suppliers
Make sure that there are reviews and monitors in place. Perhaps meetings. Perhaps reports. Perhaps dashboards. Be sure to be able to evidence that you review and monitor those suppliers. You will have processes for adverse advents so do not be surprised if you are asked to evidence an adverse event, problem or issue and that you followed your process.
#2 You have no assurance they are doing the right thing for information security
Make sure you have done your security assessment and can place your hands on an in date certificate such as an ISO27001 Certification for assurance they are doing the right thing. It needs to be in date a cover the products and / or services you have aquired and are using form the supplier.
#3 Your document and version control is wrong
Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
Why is ISO27001 Annex A 5.22 Important?
ISO27001 Annex A 5.22 Monitor, review and change management of supplier services is important because suppliers represent the biggest risk to you. If they are not doing the right thing it is your reputation, your finances, your success that is stake. Get supplier management correct and reduce the risk.
ISO27001 Annex A 5.22 FAQ
For ISO27001 Annex A 5.22 Monitor, review and change management of supplier services you will need the ISO27001 Supplier Policy: https://hightable.io/product/third-party-supplier-policy-template/
There are templates for ISO27001 Annex A 5.22 located here: https://hightable.io/iso-27001-toolkit/
ISO27001 Annex A 5.22 Sample PDF: https://hightable.io/iso-27001-toolkit/
Yes. Whilst the ISO27001 Annex A clauses are for consideration to be included in your Statement of Applicability there is no reason we can think of that would allow you to exclude ISO27001 Annex A 5.22. Monitor, review and change management of supplier services is a fundamental part of your control framework and any management system. It is explicitly required for ISO27001.
Yes. You can write the policies for ISO27001 Annex A 5.22 yourself. You will need a copy of the standard and approximately 5 days of time to do it. It would be advantageous to have a background in information security management systems. Alternatively you can download them here: https://hightable.io/iso-27001-toolkit/
ISO27001 templates for ISO27001 Annex A 5.22 are located here: https://hightable.io/iso-27001-toolkit/
ISO27001 Annex A 5.22 is hard. The documentation required is extensive. We would recommend templates to fast track your implementation.
ISO27001 Annex A 5.22 will take approximately 1 to 3 month to complete if you are starting from nothing and doing a full implementation. With the right risk management approach and an ISO27001 Template Toolkit it should take you less than 1 day.
The cost of ISO27001 Annex A 5.22 will depend how you go about it. If you do it yourself it will be free but will take you about 1 to 3 months so the cost is lost opportunity cost as you tie up resource doing something that can easily be downloaded and managed via risk management.
Matrix of controls and attribute values
- Guaranteed ISO 27001 Certification up to 10x Faster and 30x Cheaper
- The Ultimate ISO 27001 TOOLKIT so you can do it yourself
- ISO 27001 Exposed: The facts you must know (Not knowing these could cost you $10,000s!)
- 25 Things You Must Know Before Going for ISO 27001 Certification (Number 3 will blow your mind!)
- The Ultimate Reference Guide to ISO 27001 Controls
FREE 30 minute ISO27001 strategy session.
Claim your 100% FREE no-obligation 30 minute strategy session call (£1000 value). This is strictly for small businesses who are hungry to get ISO27001 certified up to 10x faster and 30x cheaper.