Why it matters
A compromised upstream dependency (a library, a hosting provider) can compromise you without any mistake on your part.
How a self-led small team implements it
List your critical infrastructure dependencies and note each one's security posture in one line — depth follows over time.
What auditors expect to see
Supply chain risk register or dependency list.
Track A.5.21 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS