A.5.19 Organizational
Information security in supplier relationships
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (13)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PS-7partialaligns with — Both controls require the organization to impose personnel-security expectations on external supplier staff who have access to organizational systems or information.
- SA-9partialaligns with — Both controls require organizations to define and enforce security and privacy requirements for external system services obtained from suppliers.
- SR-8partialaligns with — Both controls address the need for defined agreements that specify incident handling, contingency, and recovery responsibilities between the organization and its suppliers.
- SR-2nonegoverns — Both controls require the organization to develop and maintain a documented plan that identifies, assesses, and manages supply-chain security risks throughout the supplier lifecycle.
- SR-3nonegoverns — Both controls mandate the selection and implementation of specific security controls and processes that suppliers must satisfy before products or services are accepted.
- SR-6nonegoverns — Both controls require ongoing monitoring, assessment, and review of supplier performance against established security requirements.
Aligned NIST CSF 2.0 outcomes (14)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.SC-01mostlycovers — The ISO control establishes a comprehensive supplier-relationship policy and lifecycle processes that directly instantiate the CSF requirement for a documented supply-chain risk-management program.
- GV.SC-05mostlycovers — By requiring security requirements to be defined, communicated, and embedded in supplier contracts and onboarding, the control fulfills the CSF outcome of integrating cybersecurity requirements into supplier agreements.
- GV.SC-06mostlycovers — The guidance on pre-engagement due diligence, supplier evaluation, and risk assessment before formal relationships begin aligns with the CSF expectation for planning and due diligence prior to supplier onboarding.
- GV.SC-07mostlycovers — The control’s explicit risk-assessment steps for supplier products, services, and personnel map to the CSF requirement to understand, record, and prioritize risks posed by each supplier.
- GV.SC-10mostlycovers — Detailed termination procedures—including de-provisioning, asset return, and ongoing confidentiality—directly satisfy the CSF requirement for post-contract supply-chain risk-management provisions.
- GV.SC-08partialaligns with — The ISO control addresses incident handling and contingency responsibilities with suppliers, thereby supporting the CSF outcome of including suppliers in incident planning and response activities.
- ID.RA-10partialaligns with — The control’s requirement to evaluate and select suppliers based on security posture before acquisition supports the CSF outcome of assessing critical suppliers prior to acquisition.
Related OWASP ASVS 5.0 requirements (6)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (14)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1103partialmitigates — Supplier-relationship controls can require vendors to provide cross-platform support or equivalent functionality.
- CWE-1329partialmitigates — Supplier-relationship controls can require vendors to provide updateable components, but do not directly mandate component design.
- CWE-1357partialprevents — Supplier-relationship controls directly address vetting and trust of external components.
- CWE-200partialprevents — By classifying suppliers according to the sensitivity of the information they handle and requiring controls that protect confidentiality, the control lowers the likelihood that sensitive data will be exposed to unauthorized parties through the supply chain.
- CWE-269nonenone — Requiring the organization to specify and periodically review the exact privileges granted to supplier personnel and to revoke them on termination prevents unnecessary or excessive privileges from persisting.
- CWE-284nonemitigates — Requiring the organization to define exactly which supplier personnel and systems may access its information and to enforce de-provisioning at termination directly reduces the chance that unauthorized actors obtain access to resources.
- CWE-522nonenone — Requiring suppliers to implement adequate security controls and subjecting them to compliance monitoring decreases the probability that credentials or other authentication material will be stored or transmitted without sufficient protection.
- CWE-673nonemitigates — Supplier relationship controls reduce external influence on sphere definitions by third parties.
- CWE-732nonenone — The control obliges the organization to evaluate and enforce correct permission assignments on any ICT components or data that suppliers are allowed to touch, thereby reducing the risk of overly permissive resource settings.
- CWE-862nonenone — Mandating explicit access definitions and ongoing compliance monitoring for every supplier relationship prevents missing authorization checks that would otherwise allow suppliers to reach data or functions they should not.
Mitigated MITRE ATT&CK techniques (6)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1195mostlyprevents — Requiring security evaluation and selection of suppliers before onboarding reduces the likelihood that compromised or malicious products reach the organization.
- T1195.001partialmitigates — Mandating review of supplier software components and sub-components limits the introduction of tainted dependencies or development tools.
- T1584partialmitigates — Ongoing monitoring and compliance checks on supplier services make it harder for an adversary to maintain unauthorized control of supplier-hosted infrastructure used by the organization.
- T1078.004nonemitigates — Defining and de-provisioning supplier access rights at termination prevents lingering valid cloud accounts that could be abused.
- T1080nonemitigates — Controlling what suppliers can access and monitoring their use of shared content limits opportunities to taint information that downstream consumers will trust.
- T1552.005nonemitigates — Requiring suppliers to protect the organization’s information and assets reduces the chance that credentials or secrets stored in cloud instance metadata are exposed through supplier systems.
Prevented OWASP Web Top 10 (2025) risks (3)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A02partialmitigates — Requiring suppliers to implement and demonstrate adequate security controls, plus periodic compliance reviews, helps surface and correct misconfigurations introduced through external products or services.
- A03partialmitigates — By requiring evaluation, selection, and ongoing monitoring of supplier products and services—including software components and sub-components—the control directly reduces the likelihood that vulnerable or malicious third-party code enters the organization’s environment.
- A08partialmitigates — Mandating integrity checks on supplier deliverables and secure termination procedures limits the chance that tampered data or software persists after the relationship ends.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.