isms.coach
← All controls

A.5.20 · Organizational

Addressing information security within supplier agreements

Why it matters

Verbal assurances from a vendor don't hold up in an incident — contract terms do.

How a self-led small team implements it

For critical vendors, confirm their contract or DPA covers security and breach notification; for the rest, note the gap and move on.

What auditors expect to see

Contract clauses or DPAs referencing security requirements.

Track A.5.20 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.

Start your ISMS

More organizational controls