A.5.21 Organizational
Managing information security in the ICT supply chain
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (14)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- SR-2mostlyaligns with — Both controls require a documented plan that addresses supply-chain security requirements, risk management, and the identification of critical components throughout the ICT supply chain.
- SR-3mostlyaligns with — Both controls establish requirements for suppliers to flow security controls and practices down the supply chain and to verify compliance of delivered ICT products and services.
- SR-4mostlyaligns with — Both controls emphasize obtaining assurance of component provenance and traceability so that the origin and integrity of critical ICT components can be verified across the supply chain.
- SA-12partialaligns with — Both controls require the organization to protect against supply-chain threats by defining security requirements for acquired ICT products and services and by monitoring supplier performance.
- SA-22partialaligns with — Both controls require planning for component end-of-life and technology obsolescence by identifying alternative suppliers and ensuring continued availability of critical ICT components.
- SR-6partialaligns with — Both controls require ongoing assessment and review of suppliers to confirm that security requirements continue to be met and that risks are managed.
- SR-9partialaligns with — Both controls address the need to detect and prevent tampering or counterfeiting of ICT components through technical and procedural measures across the supply chain.
Aligned NIST CSF 2.0 outcomes (15)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.SC-01mostlycovers — The ISO control establishes a comprehensive ICT supply-chain security program that includes objectives, policies, and processes for managing supplier-related risks.
- GV.SC-05mostlycovers — It requires security requirements to be defined, prioritized, and embedded into supplier contracts and acquisition processes.
- GV.SC-07mostlycovers — The control mandates understanding, recording, and prioritizing risks from suppliers, their products, and sub-suppliers throughout the chain.
- GV.SC-03partialaligns with — It integrates supply-chain security practices into broader cybersecurity and enterprise risk-management activities.
- ID.AM-04partialaligns with — The control requires maintaining an inventory of services provided by suppliers to support risk and lifecycle decisions.
- ID.RA-09partialaligns with — The control requires assurance that hardware and software authenticity and integrity are verified before use.
- ID.RA-10partialaligns with — Critical suppliers are assessed for risk before acquisition and throughout the relationship.
- PR.PS-02partialaligns with — It addresses lifecycle management of supplier-provided software components, including replacement and obsolescence risks.
Related OWASP ASVS 5.0 requirements (11)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V15.1.2mostlyaligns with — The ISO control's requirement to obtain and maintain a description of software components used in acquired ICT products directly supports the ASVS mandate for an up-to-date inventory of all third-party libraries and their versions.
- V15.2.4mostlyaligns with — Requiring suppliers to propagate security requirements and ensuring components come from expected, genuine sources aligns with the ASVS requirement that third-party components and transitive dependencies are obtained only from the intended repository.
- V13.2.4partialaligns with — Defining rules for which external ICT suppliers the organization may communicate with and share supply-chain information mirrors the ASVS requirement to restrict external communications to an explicit allow-list of approved resources.
- V13.3.1partialaligns with — The ISO control's call for assurance processes and validation methods (e.g., attestation, certification) for supplier security practices aligns with the ASVS requirement to use a secure secrets-management solution that controls access to and validates critical security assets obtained from suppliers.
- V15.1.1partialaligns with — The ISO guidance to monitor and validate that delivered products meet stated security requirements corresponds to the ASVS expectation that vulnerable third-party components are remediated within documented, risk-based time frames.
Related weaknesses / CWE (11)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1329mostlymitigates — ICT supply-chain management can influence component selection toward maintainable ones, but does not guarantee technical updateability.
- CWE-829mostlyprevents — By requiring suppliers to propagate security requirements and to disclose component provenance, the control limits the inclusion of functionality obtained from untrusted third-party sources without oversight.
- CWE-1103partialmitigates — ICT supply-chain management can identify and mitigate risks from platform-dependent third-party components.
- CWE-1104partialprevents — Periodic validation, certification demands, and life-cycle monitoring of supplier components help surface and replace unmaintained third-party elements before they become exploitable liabilities.
- CWE-1357partialprevents — ICT supply-chain management is the primary control for ensuring trustworthiness of acquired components.
- CWE-494partialprevents — Mandating integrity checks, digital signatures, and origin tracing for ICT components directly reduces the chance that code or firmware lacking an integrity check will be accepted into the organisation’s environment.
- CWE-506partialprevents — Requiring suppliers to furnish component lists, attestations, and cryptographic verification of delivered artefacts makes it harder for an attacker to embed hidden malicious code that would otherwise go undetected through the supply chain.
- CWE-1188nonenone — Requiring suppliers to document secure configuration and implemented security functions reduces the likelihood that products will be initialised with insecure default settings.
Mitigated MITRE ATT&CK techniques (6)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1195fullprevents — Requiring suppliers to propagate security requirements, validate component authenticity, and trace origins throughout the ICT supply chain directly reduces the likelihood that an adversary can insert malicious code or hardware during upstream development or manufacturing.
- T1195.001mostlyprevents — Mandating disclosure of software components, cryptographic verification of integrity, and validation against stated security requirements limits an attacker’s ability to compromise build tools or dependencies before they reach the organization.
- T1195.002mostlyprevents — Requiring tamper-evidence measures, digital signatures, and traceability of critical components makes it harder for an adversary to alter or substitute software or firmware in the supply chain without detection.
- T1195.003mostlyprevents — Insisting on hardware-component provenance, anti-tamper controls, and supplier attestations reduces the chance that compromised chips or firmware are introduced via hardware vendors.
- T1588.001nonemitigates — By demanding formal certification, security-function descriptions, and ongoing monitoring of delivered products, the control makes it more difficult for adversaries to obtain or stage pre-built malware that will be accepted by the organization.
- T1608.001nonemitigates — Requiring suppliers to prove component integrity and functionality before delivery raises the bar for an adversary attempting to upload or substitute malicious artifacts into the organization’s ICT products.
Prevented OWASP Web Top 10 (2025) risks (3)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A03mostlyprevents — By mandating security requirements, component traceability, and validation of supplier practices throughout the ICT supply chain, the control directly reduces the likelihood that compromised or malicious third-party components enter the organization's applications.
- A02partialmitigates — Specifying required security functions, secure configurations, and validation methods for acquired ICT products reduces the chance that insecure default settings or misconfigurations are introduced via supplier deliverables.
- A08partialprevents — Requiring cryptographic verification, anti-tamper measures, and assurance that delivered products match their specifications helps detect and block unauthorized modification of software or data supplied by external parties.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.