A.5.21 Organizational
Managing information security in the ICT supply chain
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (29)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- SR-2mostlyaligns with — Both controls require a documented plan that addresses supply-chain security requirements, risk management, and the identification of critical components throughout the ICT supply chain.
- SR-3mostlyaligns with — Both controls establish requirements for suppliers to flow security controls and practices down the supply chain and to verify compliance of delivered ICT products and services.
- SR-4mostlyaligns with — Both controls emphasize obtaining assurance of component provenance and traceability so that the origin and integrity of critical ICT components can be verified across the supply chain.
- SA-12partialaligns with — Both controls require the organization to protect against supply-chain threats by defining security requirements for acquired ICT products and services and by monitoring supplier performance.
- SA-22partialaligns with — Both controls require planning for component end-of-life and technology obsolescence by identifying alternative suppliers and ensuring continued availability of critical ICT components.
- SR-6partialaligns with — Both controls require ongoing assessment and review of suppliers to confirm that security requirements continue to be met and that risks are managed.
- SR-9partialaligns with — Both controls address the need to detect and prevent tampering or counterfeiting of ICT components through technical and procedural measures across the supply chain.
- SA-22covers — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- SR-2governs — A.5.21's policy-level mandate to maintain agreed security levels throughout supplier relationships directly owns the supply-chain-risk-management domain that SR-2's plan operationalizes.
- SR-3governs — A.5.21's governance objective to maintain agreed security levels in supplier relationships directly mandates the domain of supply chain risk processes that SR-3 operationalizes, without naming the specific control.
- SR-4governs — A.5.21's governance objective of maintaining agreed security levels in the ICT supply chain directly encompasses the domain of provenance tracking for supplier-provided systems/components/data as one established means of assurance.
- SR-6governs — A.5.21's governance objective of maintaining agreed security levels in supplier relationships directly encompasses the supply-chain risk assessment domain that SR-6 operationalizes.
- SR-9governs — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (22)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.SC-01mostlycovers — The ISO control establishes a comprehensive ICT supply-chain security program that includes objectives, policies, and processes for managing supplier-related risks.
- GV.SC-05mostlycovers — It requires security requirements to be defined, prioritized, and embedded into supplier contracts and acquisition processes.
- GV.SC-07mostlycovers — The control mandates understanding, recording, and prioritizing risks from suppliers, their products, and sub-suppliers throughout the chain.
- GV.SC-03partialaligns with — It integrates supply-chain security practices into broader cybersecurity and enterprise risk-management activities.
- GV.SC-03partialcovers — A.5.21's focus on maintaining agreed security levels in supplier relationships addresses only a slice of GV.SC-03's broader integration of supply chain risk into enterprise risk, assessment, and improvement processes.
- ID.AM-04partialaligns with — The control requires maintaining an inventory of services provided by suppliers to support risk and lifecycle decisions.
- ID.RA-09partialaligns with — The control requires assurance that hardware and software authenticity and integrity are verified before use.
- ID.RA-10partialaligns with — Critical suppliers are assessed for risk before acquisition and throughout the relationship.
- PR.PS-02partialaligns with — It addresses lifecycle management of supplier-provided software components, including replacement and obsolescence risks.
- ID.RA-09governs — A.5.21's governance mandate to maintain agreed security levels in the ICT supply chain directly encompasses the pre-acquisition authenticity/integrity assessment named in ID.RA-09 as a core means within that domain
- ID.RA-09implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-02covers — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (11)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V15.1.2mostlyaligns with — The ISO control's requirement to obtain and maintain a description of software components used in acquired ICT products directly supports the ASVS mandate for an up-to-date inventory of all third-party libraries and their versions.
- V15.2.4mostlyaligns with — Requiring suppliers to propagate security requirements and ensuring components come from expected, genuine sources aligns with the ASVS requirement that third-party components and transitive dependencies are obtained only from the intended repository.
- V13.2.4partialaligns with — Defining rules for which external ICT suppliers the organization may communicate with and share supply-chain information mirrors the ASVS requirement to restrict external communications to an explicit allow-list of approved resources.
- V13.3.1partialaligns with — The ISO control's call for assurance processes and validation methods (e.g., attestation, certification) for supplier security practices aligns with the ASVS requirement to use a secure secrets-management solution that controls access to and validates critical security assets obtained from suppliers.
- V15.1.1partialaligns with — The ISO guidance to monitor and validate that delivered products meet stated security requirements corresponds to the ASVS expectation that vulnerable third-party components are remediated within documented, risk-based time frames.
Related weaknesses / CWE (10)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1103mitigates — ICT supply-chain management can identify and mitigate risks from platform-dependent third-party components.
- CWE-1104prevents — Periodic validation, certification demands, and life-cycle monitoring of supplier components help surface and replace unmaintained third-party elements before they become exploitable liabilities.
- CWE-1329mitigates — ICT supply-chain management can influence component selection toward maintainable ones, but does not guarantee technical updateability.
- CWE-1357prevents — ICT supply-chain management is the primary control for ensuring trustworthiness of acquired components.
- CWE-494prevents — Mandating integrity checks, digital signatures, and origin tracing for ICT components directly reduces the chance that code or firmware lacking an integrity check will be accepted into the organisation’s environment.
- CWE-506prevents — Requiring suppliers to furnish component lists, attestations, and cryptographic verification of delivered artefacts makes it harder for an attacker to embed hidden malicious code that would otherwise go undetected through the supply chain.
- CWE-829prevents — By requiring suppliers to propagate security requirements and to disclose component provenance, the control limits the inclusion of functionality obtained from untrusted third-party sources without oversight.
Mitigated MITRE ATT&CK techniques (233)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Prevented OWASP Web Top 10 (2025) risks (7)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A03mitigates — A.5.21's monitoring, validation, assurance, and anti-tampering processes bound the realized impact of a compromised/outdated supply-chain component (e.g., by detecting tampering or non-genuine parts and limiting propagation), but do not reduce the presence or exploitation success of the weakness itself.
- A05mitigates — A.5.21's supply-chain requirements (esp. f, i, j, k) can surface and limit realized injection via validated components, penetration testing, and tamper detection, but do not bound or reduce the consequence of injection that still occurs in custom code or unvetted interpreters.
- A08mitigates — A.5.21's monitoring, validation (pen-testing, attestations), assurance of no unexpected features, anti-tamper/hash/signature checks, and life-cycle processes bound the realized impact of integrity failures in delivered ICT components, but do not address insecure deserialization, CI/CD pipeline compromises, or most code/data trust issues inside the organization's own applications.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.