Outsourced Operations and Supplier Security
In ISO/IEC 27001, outsourcing an activity does not outsource accountability. The organization remains responsible for the security of information processed, stored or transmitted by external parties. Clause 8.1 (Operational planning and control) requires that externally provided processes, products… In ISO/IEC 27001, outsourcing an activity does not outsource accountability. The organization remains responsible for the security of information processed, stored or transmitted by external parties. Clause 8.1 (Operational planning and control) requires that externally provided processes, products or services relevant to the ISMS are controlled. When defining the ISMS scope (Clause 4.3), the organization must also consider interfaces and dependencies with activities performed by other organizations, so outsourced functions such as cloud hosting, managed IT services, payroll or data centres are identified rather than ignored. Supplier security is addressed mainly through Annex A organizational controls in ISO/IEC 27001:2022. Control 5.19 requires processes to manage information security risks associated with the use of supplier products and services. Control 5.20 requires relevant security requirements to be established and agreed in supplier agreements, for example confidentiality, access control, incident notification, right to audit, subcontracting conditions and return or destruction of data at contract end. Control 5.21 addresses risks in the ICT products and services supply chain. Control 5.22 requires regular monitoring, review, evaluation and change management of supplier service delivery and security practices. Control 5.23 covers acquiring, using, managing and exiting cloud services. These link to risk assessment (Clause 6.1.2), because supplier risks must be identified, analysed and treated like any other risk. From a Lead Auditor perspective, the auditor seeks objective evidence that the organization knows its critical suppliers, has classified them by risk, has performed due diligence before engagement, includes enforceable security clauses in contracts, and actively monitors performance through service reports, audits, certifications such as ISO/IEC 27001 or SOC reports, and incident reviews. The auditor also checks that changes to supplier services are assessed for security impact and that exit or termination arrangements protect information. Weaknesses such as unsigned agreements, no security requirements in contracts, or no evidence of supplier review are typical sources of nonconformities. Effective supplier security ensures that the confidentiality, integrity and availability of information are preserved across the entire extended enterprise.
Outsourced Operations and Supplier Security in ISO/IEC 27001: A Complete Guide for Lead Auditors
Introduction
Modern organizations rarely operate alone. Cloud hosting, payroll processing, software development, data centres, managed security services, logistics and customer support are routinely outsourced. Every outsourced activity extends the organization's information security risk beyond its own walls.
ISO/IEC 27001:2022 addresses this through two sets of requirements:
- The management system clauses, especially Clause 8.1, which requires the organization to determine and control externally provided processes, products or services relevant to the ISMS.
- The Annex A organizational controls 5.19 to 5.23, which address supplier relationships and cloud services.
For an ISO 27001 Lead Auditor, understanding this topic is essential. Auditors must judge whether the organization keeps accountability for information security even when it delegates activities.
Why It Is Important
1. Accountability cannot be outsourced. An organization can outsource a process, but it remains fully responsible for the security of its information and for meeting its legal, regulatory and contractual obligations. If a cloud provider leaks customer data, regulators and customers will hold the data owner accountable.
2. The supply chain is an attack vector. Many major breaches came through suppliers, such as compromised software updates, managed service providers with privileged remote access, or HVAC vendors with network credentials. Supplier weaknesses become the organization's weaknesses.
3. ISMS scope and boundaries. Clause 4.3 requires the organization to define interfaces and dependencies between its own activities and those performed by other organizations. Outsourced processes often sit on these boundaries.
4. Risk-based thinking. Clauses 6.1.2 and 8.2 require information security risks to be identified and assessed. Risks arising from suppliers must be part of this assessment.
5. Business continuity and resilience. Dependence on a single supplier can create critical points of failure. Supplier security therefore affects availability as well as confidentiality and integrity.
6. Legal and regulatory compliance. Many regulations require controls over data processors and third parties. Examples include GDPR Article 28, DORA, NIS2 and sector-specific rules.
What It Is
Outsourced operations are processes or functions relevant to the ISMS that an external party performs on the organization's behalf. Examples include IT infrastructure management, application hosting, backup services, security monitoring (SOC), physical security guarding and document destruction.
Supplier security is the set of policies, processes and controls used to manage information security risks across the full lifecycle of supplier relationships. That lifecycle runs from selection and contracting through monitoring, change and termination.
Key ISO/IEC 27001:2022 requirements
- Clause 4.3 (Scope): consider interfaces and dependencies with external parties.
- Clause 6.1.3 (Risk treatment): select controls, including supplier controls, and justify inclusion or exclusion in the Statement of Applicability.
- Clause 8.1 (Operational planning and control): the organization shall ensure that externally provided processes, products or services relevant to the ISMS are controlled.
Annex A controls (2022 version)
- 5.19 Information security in supplier relationships: define and implement processes to manage risks associated with the use of supplier products or services.
- 5.20 Addressing information security within supplier agreements: establish and agree relevant security requirements with each supplier, based on the type of relationship.
- 5.21 Managing information security in the ICT supply chain: address risks in the ICT product and service supply chain, including sub-suppliers (fourth parties).
- 5.22 Monitoring, review and change management of supplier services: regularly monitor, review, evaluate and manage changes in supplier security practices and service delivery.
- 5.23 Information security for use of cloud services: establish processes for acquiring, using, managing and exiting cloud services. This control is new in 2022.
Related controls
- 5.14 Information transfer
- 5.31 Legal, statutory, regulatory and contractual requirements
- 5.34 Privacy and protection of PII
- 8.30 Outsourced development
- 6.6 Confidentiality or non-disclosure agreements
- 5.29 Information security during disruption
Mapping from the 2013 version
For candidates who studied the older standard:
- A.15.1.1, A.15.1.2 and A.15.1.3 became 5.19, 5.20 and 5.21.
- A.15.2.1 and A.15.2.2 merged into 5.22.
- A.14.2.7 became 8.30.
- 5.23 Cloud services is new.
Guidance standards
- ISO/IEC 27002:2022 gives implementation guidance.
- ISO/IEC 27036 (all parts) addresses supplier relationships.
- ISO/IEC 27017 and 27018 address cloud security and PII in the cloud.
How It Works: The Supplier Security Lifecycle
1. Policy and planning
The organization defines a supplier security policy or topic-specific policy. It identifies supplier types (IT, cloud, logistics, utilities, consultants) and classifies them by criticality and access to information.
2. Risk assessment
Before engaging a supplier, the organization assesses the risks. Typical questions include:
- What information will the supplier access, process or store?
- What is its classification?
- What is the impact if the supplier fails?
3. Due diligence and selection
The organization evaluates the supplier's security capability. Common sources of evidence are:
- Questionnaires
- Certifications such as ISO 27001, with a check that the certificate scope covers the service being bought
- SOC 2 reports
- Penetration test summaries
- On-site audits
4. Contractual agreements
Security requirements are embedded in contracts, SLAs, NDAs and data processing agreements. Typical clauses cover:
- Confidentiality
- Access control
- Incident notification timelines
- Right to audit
- Subcontracting restrictions and flow-down of requirements
- Data location
- Return and destruction of data at termination
- Legal and regulatory compliance
- Business continuity
- Vulnerability management
- Acceptable use
5. Onboarding and access provisioning
Suppliers receive only the minimum access required (least privilege), supported by awareness of relevant policies.
6. Monitoring and review
The organization regularly reviews supplier performance and security. Typical activities include:
- Service reports
- KPI reviews
- Second-party audits
- Review of independent audit reports
- Incident reviews
- Tracking corrective actions
7. Change management
Changes to supplier services, such as new subcontractors, new data centres, policy changes or technology changes, are assessed for their effect on risk.
8. Incident management
Suppliers report incidents promptly according to agreed procedures, and joint responses are coordinated.
9. Termination and exit
When a relationship ends, the organization should:
- Revoke access
- Return or securely destroy information
- Transfer knowledge
- Ensure continuity through exit strategies, which are especially important for cloud services (5.23)
Types of control over outsourced processes
The extent of control depends on the risk and on the supplier's capability. Organizations may use:
- Contractual controls
- Monitoring of performance
- Verification activities such as audits and inspections
- Acceptance testing of products
- Shared management reviews
Cloud services: shared responsibility
For cloud services, the organization must understand the shared responsibility model. The cloud provider secures the underlying infrastructure. The customer remains responsible for configuration, identity and access management, and data classification. It also remains responsible for encryption choices and how the service is used.
How an Auditor Evaluates This Area
A Lead Auditor gathers objective evidence through interviews, document review and observation. Typical audit activities include the following.
Check scope and dependencies
- Is there a list or register of suppliers and outsourced processes relevant to the ISMS?
Check risk-based classification
- Are suppliers categorized by risk?
- Do critical suppliers receive more rigorous controls?
Sample contracts
- Do agreements contain the security requirements identified in the risk assessment?
- Do they include a right to audit?
- Do they set breach notification timeframes?
Check due diligence evidence
- Were suppliers evaluated before selection?
- If a supplier holds an ISO 27001 certificate, does its scope actually cover the service provided?
Check monitoring evidence
- Look for review meeting minutes, SLA reports and audit reports of suppliers.
- Look for follow-up of nonconformities.
Check access
- Are supplier accounts reviewed and removed when no longer needed?
Check termination records
- For ended contracts, is there evidence of data return or destruction and access revocation?
Check the Statement of Applicability
- Are controls 5.19 to 5.23 and 8.30 included or justifiably excluded?
Typical nonconformities
- A critical cloud provider is not included in the risk assessment.
- Contracts lack security clauses or incident notification requirements.
- There is no evidence of periodic supplier review.
- Supplier accounts remain active after contract end.
- The organization relies on a supplier's certificate whose scope does not cover the purchased service.
- Subcontracting by the supplier is uncontrolled.
- No exit strategy exists for a critical SaaS application.
Exam Tips: Answering Questions on Outsourced Operations and Supplier Security
Tip 1: Remember the golden rule. Responsibility and accountability for information security always remain with the organization, even when processes are outsourced. Any answer option suggesting that outsourcing transfers responsibility to the supplier is almost always wrong.
Tip 2: Know the clause and control numbers.
- Clause 8.1 covers control of externally provided processes, products or services.
- Annex A 5.19 to 5.23 cover supplier relationships and cloud services.
- Annex A 8.30 covers outsourced development.
Exams often ask which clause or control applies to a scenario.
Tip 3: Think risk-based. The level of control applied to a supplier should be proportional to the risk. If a question asks what an organization should do first when engaging a new supplier, the answer is usually to identify and assess the risks and define security requirements.
Tip 4: Certification is not a blank cheque. In scenario questions, check whether a supplier's ISO 27001 certificate covers the specific service and location involved. A certificate alone does not prove that contractual requirements are met. It also does not remove the need for monitoring.
Tip 5: Contracts are central evidence. Expect questions about which elements belong in supplier agreements, such as:
- Confidentiality
- Right to audit
- Incident reporting
- Subcontracting
- Data return and destruction
- Compliance obligations
If a scenario shows an incident with no agreed notification process, that points to a nonconformity against 5.20 and possibly 5.22.
Tip 6: Distinguish the controls.
- 5.19 is the overall process and policy for supplier relationships.
- 5.20 is the content of agreements.
- 5.21 is the ICT supply chain, including sub-suppliers.
- 5.22 is ongoing monitoring and change management.
- 5.23 is the cloud service lifecycle, including exit.
Match the evidence in a scenario to the most specific control.
Tip 7: Writing nonconformity statements. In case study questions, a good nonconformity statement has three parts:
- The requirement, for example: ISO/IEC 27001 Annex A 5.22 requires the organization to regularly monitor, review and evaluate supplier service delivery.
- The evidence, for example: no review records existed for the managed SOC provider for the past 18 months.
- The nonconformity, for example: the organization has not demonstrated monitoring of a critical supplier.
Keep the statement factual, objective and traceable.
Tip 8: Major or minor?
- A major nonconformity is typically a systemic failure, such as no supplier management process at all, or critical outsourced processes completely uncontrolled.
- A minor nonconformity is typically an isolated lapse, such as one contract missing a clause while others are compliant.
Justify your grading by the effect on the ISMS's ability to achieve its intended outcomes.
Tip 9: Auditing the supplier vs auditing the client. During a third-party certification audit, the auditor audits the client organization's control over its suppliers. The auditor does not normally audit the supplier itself. Questions may test whether you know to look for evidence of the client's management of the supplier rather than going to the supplier's premises.
Tip 10: Watch for the cloud shared responsibility trap. If a scenario says the organization assumes its cloud provider handles all security, recognize this as a gap. The customer remains responsible for its share, such as configuration, access and data protection, and must have processes under 5.23.
Tip 11: Do not forget termination. Exam scenarios often hide an issue in the exit phase. Look for former supplier accounts still active, or data never returned or deleted. Link these to supplier agreement requirements and access rights management (5.18).
Tip 12: Use the PDCA logic.
- Plan: policy, risk assessment and requirements.
- Do: contracts, onboarding and controls.
- Check: monitoring and audits.
- Act: corrective actions and changes.
If an organization only selects suppliers carefully but never reviews them, the Check stage is missing.
Tip 13: Read every word of the question. Words such as first, best, most appropriate and primarily matter. When several answers are plausible, pick the one that is most risk-based, most aligned with the standard's wording and most clearly retains organizational accountability.
Summary
Outsourced operations and supplier security ensure that information security is not weakened when work moves outside the organization's boundaries. ISO/IEC 27001 requires organizations to:
- Determine and control externally provided processes (Clause 8.1).
- Manage supplier risks across the full lifecycle (Annex A 5.19 to 5.23 and 8.30).
For a Lead Auditor, the key is verifying, through objective evidence, that the organization has identified its suppliers and assessed their risks. The auditor should also confirm that the organization has contractually defined requirements and that it monitors performance, manages changes and exits safely. Above all, remember: you can outsource the work, but never the accountability.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!