11. Supplier Relationships
This category ensures that information security risks related to supplier relationships are identified and managed. It includes establishing and maintaining agreements with suppliers, monitoring supplier services, and ensuring that suppliers adhere to information security policies and requirements.
Controls (A.15):
Control A.15.1.1: Information Security Policy for Supplier Relationships
Control A.15.1.2: Addressing Security Within Supplier Agreements
Control A.15.1.3: Information and Communication Technology Supply Chain
Control A.15.2.1: Monitoring and Review of Supplier Services
Control A.15.2.2: Managing Changes to Supplier Services
Previous10. System Acquisition, Development, and MaintenanceNext12: Information Security Incident Management
Last updated