ISO 27001 Annex A 5.20 Addressing Information Security Within Supplier Agreements (The Unofficial Zero BS Guide)

ISO 27001 Annex A 5.20

ISO 27001 Annex A 5.20 Addressing information security within supplier agreements requires organisations to define and agree security terms with every vendor. Documented clauses ensure suppliers protect company data, control system access, and meet legal duties.

Key Takeaways

  • Establish binding security terms: Agree on formal security clauses in every contract before granting third-party access to company assets.
  • Store agreements centrally: Keep signed vendor contracts, non-disclosure agreements, and security addendums in a central document repository.
  • Define data handling rules: State clear requirements for how suppliers access, process, store, encrypt, and return business records.
  • Mandate incident reporting: Require suppliers to report data breaches, outages, and security vulnerabilities within defined contract deadlines.
  • Secure right to audit: Include terms allowing your organisation or third-party assessors to audit vendor security controls regularly.
  • Govern subcontractor risks: Require primary suppliers to pass equivalent security obligations down to their own sub-processors.
  • Plan for contract termination: Define clear exit steps, including account cancellation, hardware return, and verified data destruction.
  • Review contracts periodically: Update agreement templates when business requirements, privacy laws, or ISO standards change.

How to Implement ISO 27001 Annex A 5.20

  • Draft standard security schedules: Create approved security terms and data protection addendums and store them in your central document repository.
  • Classify suppliers by risk: Categorise vendors by data sensitivity to determine whether standard or enhanced security clauses apply.
  • Define access boundaries: State explicitly which networks, systems, and file types the supplier can access during contract work.
  • Set incident notification targets: Specify mandatory time limits, such as twenty-four hours, for vendors to notify you of security incidents.
  • Include disaster recovery rules: Require suppliers to maintain tested business continuity plans and meet target availability service levels.
  • Establish screening standards: Require vendors to screen personnel assigned to work on your systems or handle sensitive files.
  • Mandate data return and deletion: Include explicit clauses requiring suppliers to return or securely wipe all business data upon contract completion.
  • Train procurement teams: Educate purchasing staff and contract owners on how to embed security schedules into standard vendor agreements.
  • Maintain a central contract log: Record all executed supplier agreements, key security clauses, and renewal dates in a central register.

When you’re ready to bring compliance into one place

High Table Compliance Platform powered by hicomply
High Table Compliance Platform powered by hicomply

How to Audit ISO 27001 Annex A 5.20

  • Review agreement policies: Inspect written supplier procedures to verify standard methods exist for addressing security within vendor contracts.
  • Sample active supplier contracts: Audit a random selection of vendor files to verify fully executed contracts contain agreed security terms.
  • Verify pre-access execution dates: Compare contract signature dates against account creation timestamps to ensure agreements came first.
  • Check audit clause inclusion: Confirm sampled contracts explicitly include rights to audit vendor security controls or receive third-party reports.
  • Inspect incident reporting clauses: Check that agreements clearly define vendor duties to report data leaks and outages on time.
  • Verify data sanitisation terms: Confirm agreements require verified data deletion or return upon contract termination.
  • Review non-standard contract approvals: Inspect legal and security sign-offs for vendor-supplied agreements containing modified terms.
  • Check subcontractor pass-through terms: Verify that contracts obligate suppliers to bind their sub-processors to matching security standards.

Audit Evidence Checklist

  • Supplier security policy: Maintain a documented supplier agreement procedure with full version history in your central repository.
  • Standard agreement templates: Supply approved security addendums, non-disclosure templates, and master service terms.
  • Countersigned supplier contracts: Provide executed agreements for sampled suppliers demonstrating agreed security clauses.
  • Central supplier register: Keep an active log of all contracted third parties, risk ratings, and contract owners.
  • Non-standard contract reviews: Supply documented security risk reviews and sign-offs for custom vendor terms.
  • Disposal certificates from exits: Provide verified data destruction receipts from suppliers offboarded during the audit period.
  • Procurement training logs: Show sign-off sheets proving contract negotiators completed training on supplier security requirements.

What to Teach Employees

  • Sign before sharing data: Teach staff never to share company files or provide system access without an executed security agreement.
  • Use standard templates: Instruct team members to use pre-approved legal templates and avoid modifying security terms without guidance.
  • Involve legal and security leads: Remind contract owners to route vendor-provided agreements through formal security reviews.
  • Know vendor breach duties: Teach managers how to enforce agreed reporting timelines when a supplier encounters an operational incident.
  • Enforce exit steps: Instruct staff to request confirmation of data deletion and cancel access immediately when vendor work ends.
  • Report uncontracted suppliers: Encourage workers to flag any unrecorded software or services used by teams without formal contracts.

Common Implementation Challenges

  • Accepting standard vendor terms: Small businesses sign click-through terms that lack security protections. Request standard compliance addendums.
  • Granting access before signing: Project teams grant system accounts before completing contracts. Block access creation until agreements are filed.
  • Vague data protection terms: Agreements state security broadly without measurable rules. Define explicit encryption, access, and logging standards.
  • Overlooking informal contractors: Freelancers work under purchase orders without security clauses. Require standard security addendums for all contractors.
  • Missing central repositories: Signed agreements stay in personal email folders. Store all executed contracts in a single central repository.
  • Ignoring contract expiry: Projects continue long after fixed-term agreements expire. Track renewal dates within a central contract register.

How to Measure Effectiveness (KPIs)

  • Supplier contract coverage rate: Track the percentage of active third-party suppliers with countersigned security terms on file.
  • Pre-access agreement compliance: Measure the proportion of vendor accounts created only after contracts were fully executed.
  • Contract repository accuracy: Measure the proportion of active vendor relationships matching central records during quarterly audits.
  • Supplier security breach count: Monitor the total number of security incidents or data breaches originating from contracted vendors.
  • Custom term review rate: Track the percentage of non-standard vendor agreements reviewed and approved by security leads.
  • Supplier agreement audit findings: Count the number of non-conformities raised against supplier contract terms during internal audits.

ISO 27001 Control A 5.20 connects to several other ISO 27001 requirements:

Annex A 5.19 provides the high-level policy for supplier relationships. Annex A 5.20 turns that policy into legally binding contractual terms. This control also supports Clause 8.1 regarding operational planning. It ensures third parties do not introduce unmanaged risks into your environment. Proper mapping requires linking these clauses within your internal wiki.

ISO 27001 Addressing Information Security Within Supplier Agreements Explained - Annex A 5.20 - High Table Compliance Platform powered by hicomply
High Table Compliance Platform powered by hicomply