A.5.22 Organizational
Monitoring, review and change management of supplier services
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (14)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CA-7mostlyaligns with — The ISO control’s continuous monitoring of supplier performance, incidents, and changes mirrors NIST’s requirement for ongoing control monitoring and assessment of external services.
- CM-3partialaligns with — The ISO control’s explicit tracking and review of supplier-initiated changes parallels NIST’s configuration-change control process for externally provided components.
- IR-4partialaligns with — Both require structured handling of security incidents that originate from or affect supplier services, including coordination and follow-up actions.
- SR-2partialaligns with — The ISO guidance operationalizes the supplier risk management plan by specifying the monitoring, review, and change-management activities needed to keep the plan effective.
- SR-6nonegoverns — Both controls establish ongoing supplier assessment and review activities to verify that external providers continue to meet security and service obligations.
- CA-7governs — A.5.22's governance of supplier service monitoring, review, and change directly requires the kind of ongoing metrics-driven system-level continuous monitoring that ca-7 operationalizes within the supplier-agreement domain
- SR-2governs — A.5.22's mandate to monitor/review/change supplier services to maintain agreed security levels directly sits inside the supply-chain risk management domain that SR-2 requires a plan for, without naming the specific plan artifact.
Aligned NIST CSF 2.0 outcomes (20)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- DE.CM-06mostlyaligns with — The control's explicit requirement to monitor external service provider activities and service changes fulfills the CSF outcome of detecting potentially adverse events arising from third-party services.
- DE.CM-06mostlycovers — A.5.22's monitoring/review/change-management of supplier services to maintain agreed security levels directly accounts for the bulk of DE.CM-06's requirement to monitor external providers for adverse events; a residual of DE.CM-06's broader 'potentially adverse events' scope (including non-contractual indicators) sits outside A.5.22's agreement-centric focus
- GV.SC-07mostlyaligns with — By requiring continuous evaluation of supplier performance, incidents, vulnerabilities, and sub-supplier relationships, the control produces the understanding, recording, and prioritization of supplier-related risks that the CSF outcome expects.
- GV.SC-09mostlyaligns with — The ISO control's ongoing monitoring, review, and change-management activities for supplier services directly support the CSF outcome of integrating supply-chain security practices into broader cybersecurity and enterprise risk management programs.
- GV.SC-03partialaligns with — Embedding supplier-service monitoring and incident handling into the organization's risk-management processes mirrors the CSF outcome of integrating supply-chain risk management into enterprise risk activities.
- ID.RA-10partialaligns with — Regular post-acquisition reviews of supplier security levels and sub-supplier relationships extend the CSF outcome's pre-acquisition assessment of critical suppliers into ongoing risk evaluation.
- RS.MA-01partialaligns with — The control's requirement to respond to and manage supplier-related security incidents in coordination with the supplier aligns with the CSF outcome of executing the incident response plan together with relevant third parties.
- GV.SC-03governs — GV.SC-03 names the integration of supply-chain risk into enterprise processes; A.5.22's monitoring/review/change-management of supplier services is a principal technical means that sits inside that exact domain, reached by subject membership rather than explicit naming of the requirement.
- GV.SC-03implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.RA-10implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.RA-10governs — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- RS.MA-01governs — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- RS.MA-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (6)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (7)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1103mitigates — Ongoing monitoring of supplier services can detect and drive remediation of platform-dependency issues.
- CWE-1357finds — Ongoing monitoring and change management of supplier services mitigates drift in component trustworthiness.
- CWE-200finds — Regular review of supplier audit trails, incident reports and service records reduces the likelihood that sensitive data will remain exposed through inadequate handling by the supplier.
- CWE-284finds — Ongoing audits and performance reviews of suppliers detect and correct situations where access controls or privilege assignments are weaker than contractually required, limiting an attacker's ability to exploit improper access control in the supplier's environment.
- CWE-732finds — Monitoring supplier policy changes and conducting audits can reveal incorrect permission assignments on resources managed by the supplier, prompting corrective action before they are exploited.
Mitigated MITRE ATT&CK techniques (186)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Prevented OWASP Web Top 10 (2025) risks (8)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A03finds — A.5.22 explicitly requires monitoring supplier changes, conducting audits of suppliers/sub-suppliers, reviewing audit trails/records/incidents/vulnerabilities, and evaluating security levels, which surfaces vulnerable/outdated/compromised dependencies and related supply-chain issues (the category's largest slice) but does not address build pipelines or signing infrastructure at all.
- A03mitigates — A.5.22's monitoring/review of supplier changes, incidents, vulnerabilities, audits and service continuity bounds the realized impact of a supply-chain failure (e.g. by catching and responding to a compromised dependency or sub-supplier) without preventing the weakness from being present or removing it.
- A03remediates — A.5.22 requires monitoring/review of supplier services plus follow-up actions on identified issues (including new/changed controls for incidents, vulnerability management, and ensuring adequate security levels), which can lead to remediation of vulnerable/outdated supplier dependencies or sub-supplier issues but does not itself perform the removal and stops short of build pipelines or signing infrastructure.
- A09finds — A.5.22 explicitly requires monitoring supplier service performance, reviewing reports/audit trails/events, conducting audits, identifying vulnerabilities, and managing incidents, which surfaces logging/alerting failures when they affect the supplier relationship or service delivery.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.