A.5.22 Organizational
Monitoring, review and change management of supplier services
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (10)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CA-7mostlyaligns with — The ISO control’s continuous monitoring of supplier performance, incidents, and changes mirrors NIST’s requirement for ongoing control monitoring and assessment of external services.
- CM-3partialaligns with — The ISO control’s explicit tracking and review of supplier-initiated changes parallels NIST’s configuration-change control process for externally provided components.
- IR-4partialaligns with — Both require structured handling of security incidents that originate from or affect supplier services, including coordination and follow-up actions.
- SR-2partialaligns with — The ISO guidance operationalizes the supplier risk management plan by specifying the monitoring, review, and change-management activities needed to keep the plan effective.
- SR-6nonegoverns — Both controls establish ongoing supplier assessment and review activities to verify that external providers continue to meet security and service obligations.
Aligned NIST CSF 2.0 outcomes (11)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- DE.CM-06mostlyaligns with — The control's explicit requirement to monitor external service provider activities and service changes fulfills the CSF outcome of detecting potentially adverse events arising from third-party services.
- GV.SC-07mostlyaligns with — By requiring continuous evaluation of supplier performance, incidents, vulnerabilities, and sub-supplier relationships, the control produces the understanding, recording, and prioritization of supplier-related risks that the CSF outcome expects.
- GV.SC-09mostlyaligns with — The ISO control's ongoing monitoring, review, and change-management activities for supplier services directly support the CSF outcome of integrating supply-chain security practices into broader cybersecurity and enterprise risk management programs.
- GV.SC-03partialaligns with — Embedding supplier-service monitoring and incident handling into the organization's risk-management processes mirrors the CSF outcome of integrating supply-chain risk management into enterprise risk activities.
- ID.RA-10partialaligns with — Regular post-acquisition reviews of supplier security levels and sub-supplier relationships extend the CSF outcome's pre-acquisition assessment of critical suppliers into ongoing risk evaluation.
- RS.MA-01partialaligns with — The control's requirement to respond to and manage supplier-related security incidents in coordination with the supplier aligns with the CSF outcome of executing the incident response plan together with relevant third parties.
Related OWASP ASVS 5.0 requirements (6)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (9)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1103partialmitigates — Ongoing monitoring of supplier services can detect and drive remediation of platform-dependency issues.
- CWE-1357partialfinds — Ongoing monitoring and change management of supplier services mitigates drift in component trustworthiness.
- CWE-200partialfinds — Regular review of supplier audit trails, incident reports and service records reduces the likelihood that sensitive data will remain exposed through inadequate handling by the supplier.
- CWE-284partialfinds — Ongoing audits and performance reviews of suppliers detect and correct situations where access controls or privilege assignments are weaker than contractually required, limiting an attacker's ability to exploit improper access control in the supplier's environment.
- CWE-732partialfinds — Monitoring supplier policy changes and conducting audits can reveal incorrect permission assignments on resources managed by the supplier, prompting corrective action before they are exploited.
- CWE-400nonenone — Service-performance monitoring and capacity reviews can identify uncontrolled resource consumption by the supplier before it degrades agreed service levels or creates denial-of-service conditions.
- CWE-778nonenone — Requiring suppliers to maintain and share audit trails and event records ensures that security-relevant activity is captured, reducing the impact of insufficient logging within the supplier's systems.
Mitigated MITRE ATT&CK techniques (5)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1195mostlydetects — Ongoing monitoring of supplier changes, sub-contracting, and new technologies reduces the likelihood that a compromised or malicious supplier component reaches the organization undetected.
- T1199mostlydetects — Continuous oversight of supplier relationships and sub-supplier changes limits the abuse of trusted third-party connections to gain initial access.
- T1078partialdetects — Requiring suppliers to maintain agreed security levels and promptly address incidents reduces the chance that valid supplier credentials or accounts are misused to access the organization.
- T1584partialdetects — Regular audits and review of supplier service reports and security events make it harder for an adversary to maintain long-term control of supplier infrastructure used against the organization.
- T1588nonemitigates — Reviewing supplier policy changes, new controls, and audit trails makes it more difficult for an adversary to obtain or develop capabilities through the supplier channel without detection.
Prevented OWASP Web Top 10 (2025) risks (4)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A02partialfinds — Regular audits, review of supplier policies, and verification of control effectiveness help detect and correct insecure configurations or missing hardening measures that originate from or are maintained by external service providers.
- A03partialfinds — Ongoing monitoring of supplier changes, sub-supplier relationships, and service enhancements reduces the likelihood that third-party code, components, or updates introduce vulnerable or malicious artifacts into the organization's applications.
- A08partialfinds — Reviewing supplier audit trails, incident information, and change records enables early identification of integrity issues such as unauthorized modifications or tampering introduced through the supply chain.
- A09partialmitigates — Requiring suppliers to provide incident data, audit trails, and event records, then reviewing them, extends the organization's visibility into security-relevant events that would otherwise remain hidden in external environments.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.