ISO 27001 5.19 Information Security in Supplier Relationships Requirement:
"Processes and procedures shall be defined and implemented to manage the information security risks associated with the use of supplier’s products or services."[1]
ISO 27001 5.19 Information Security in Supplier Relationships Requirement Explanation:
Define which suppliers need to meet security requirements established by your organization. Types of suppliers that should meet security requirements include SAAS servic providers your organization uses and suppliers with access to your information system. You can require that service provides hold a specific certification (ISO 27001) or meet your specific security requirements.
References:
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you