A.5.19 Organizational
Information security in supplier relationships
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (23)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PS-7mostlycovers — A.5.19's broad requirement to maintain agreed security levels in all supplier relationships fully accounts for the external-provider compliance, notification, and documentation aspects of PS-7, but leaves a residual slice (explicitly establishing the organization's own internal personnel security roles/responsibilities that providers must then follow) uncovered by the supplier-relationship control.
- SA-9mostlycovers — A.5.19's broad requirement to maintain agreed security levels in all supplier relationships accounts for the bulk of SA-9's provider-compliance and oversight mandates, but leaves a residual slice (explicit privacy requirements, defined monitoring processes/techniques, and user-role documentation) uncovered by the ISO control's wording.
- PS-7partialaligns with — Both controls require the organization to impose personnel-security expectations on external supplier staff who have access to organizational systems or information.
- SA-9partialaligns with — Both controls require organizations to define and enforce security and privacy requirements for external system services obtained from suppliers.
- SR-8partialaligns with — Both controls address the need for defined agreements that specify incident handling, contingency, and recovery responsibilities between the organization and its suppliers.
- SR-2nonegoverns — Both controls require the organization to develop and maintain a documented plan that identifies, assesses, and manages supply-chain security risks throughout the supplier lifecycle.
- SR-3nonegoverns — Both controls mandate the selection and implementation of specific security controls and processes that suppliers must satisfy before products or services are accepted.
- SR-6nonegoverns — Both controls require ongoing monitoring, assessment, and review of supplier performance against established security requirements.
- SR-8governs — A.5.19's broad governance mandate for maintaining agreed security levels in all supplier relationships directly encompasses the supply-chain notification agreements required by SR-8 as one subject within that domain.
Aligned NIST CSF 2.0 outcomes (17)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.SC-01mostlycovers — The ISO control establishes a comprehensive supplier-relationship policy and lifecycle processes that directly instantiate the CSF requirement for a documented supply-chain risk-management program.
- GV.SC-05mostlycovers — By requiring security requirements to be defined, communicated, and embedded in supplier contracts and onboarding, the control fulfills the CSF outcome of integrating cybersecurity requirements into supplier agreements.
- GV.SC-06mostlycovers — The guidance on pre-engagement due diligence, supplier evaluation, and risk assessment before formal relationships begin aligns with the CSF expectation for planning and due diligence prior to supplier onboarding.
- GV.SC-07mostlycovers — The control’s explicit risk-assessment steps for supplier products, services, and personnel map to the CSF requirement to understand, record, and prioritize risks posed by each supplier.
- GV.SC-10mostlycovers — Detailed termination procedures—including de-provisioning, asset return, and ongoing confidentiality—directly satisfy the CSF requirement for post-contract supply-chain risk-management provisions.
- GV.SC-08partialaligns with — The ISO control addresses incident handling and contingency responsibilities with suppliers, thereby supporting the CSF outcome of including suppliers in incident planning and response activities.
- GV.SC-08partialcovers — A.5.19's broad requirement to maintain agreed security levels in supplier relationships can include clauses on incident planning/response/recovery, addressing a slice of GV.SC-08 but not its full scope of explicit inclusion and operational integration in those activities.
- ID.RA-10partialaligns with — The control’s requirement to evaluate and select suppliers based on security posture before acquisition supports the CSF outcome of assessing critical suppliers prior to acquisition.
- ID.RA-10implements — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (6)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (10)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-284nonemitigates — Requiring the organization to define exactly which supplier personnel and systems may access its information and to enforce de-provisioning at termination directly reduces the chance that unauthorized actors obtain access to resources.
- CWE-673nonemitigates — Supplier relationship controls reduce external influence on sphere definitions by third parties.
- CWE-1103mitigates — Supplier-relationship controls can require vendors to provide cross-platform support or equivalent functionality.
- CWE-1329mitigates — Supplier-relationship controls can require vendors to provide updateable components, but do not directly mandate component design.
- CWE-1357prevents — Supplier-relationship controls directly address vetting and trust of external components.
- CWE-200prevents — By classifying suppliers according to the sensitivity of the information they handle and requiring controls that protect confidentiality, the control lowers the likelihood that sensitive data will be exposed to unauthorized parties through the supply chain.
Mitigated MITRE ATT&CK techniques (161)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Prevented OWASP Web Top 10 (2025) risks (6)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A03mitigates — A.5.19 requires risk assessment, monitoring, compliance mitigation, incident handling, resilience measures and secure termination processes that bound the blast radius or downstream impact of realized supply-chain failures (e.g. compromised dependencies or pipelines), but does not itself limit or contain an already-present vulnerable/outdated component or signing flaw.
- A03remediates — A.5.19 explicitly requires identifying, assessing, mitigating non-compliance, handling incidents, and implementing secure termination/transfer/recovery processes that include replacing or switching suppliers (including advance identification of alternatives), which removes the vulnerable/outdated/compromised dependency or pipeline element from the organization's environment.
- A08mitigates — A.5.19 requires assessing/managing supplier risks (incl. product vulnerabilities and integrity of supplier info/processing), monitoring compliance, mitigating non-compliance, and defining secure supplier processes that bound the blast radius or consequence of an integrity failure in supplier code/data without preventing the weakness itself.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.