Skip to content
atlas

Supplier management

Also known as: supply-chain security, third-party risk management, vendor management

Making sure outside partners who handle your data or systems meet your security demands.

Draft - this entry has not been reviewed yet.

Formal

The ongoing process of selecting, contracting, monitoring and exiting suppliers - as required by NIS2 Article 21(2)(d) and ISO 27002 controls 5.19-5.22 - so that the risks they bring are known and kept within the organisation's accepted limits.

In plain English

You lock your own front door, but you also check that the cleaning company holding a spare key looks after it properly.

In practice

Before a Danish hospital lets the maker of its infusion pumps log in remotely for maintenance, the procurement officer asks for the supplier's security report, writes breach-notice terms into the contract and books a yearly review.

Why it matters

Attackers often go through the weakest supplier to reach many customers at once, so an organisation's security is only as strong as that of the partners it lets in.

Technical deep dive

ISO/IEC 27002:2022 splits the topic into five controls: 5.19 (information security in supplier relationships: define processes to manage the risks of using suppliers' products and services), 5.20 (addressing information security in supplier agreements), 5.21 (managing information security in the ICT supply chain, including sub-suppliers and components), 5.22 (monitoring, review and change management of supplier services) and 5.23 (information security for use of cloud services, new in 2022, covering acquisition, use, management and exit). The guidance assumes a lifecycle: classify suppliers by criticality and data access, set requirements before contracting, embed them in the agreement, monitor during the relationship and manage termination, including return or deletion of data and revocation of access.

Legal drivers stack on top. NIS2 Article 21(2)(d) requires supply chain security, including security-related aspects of relationships with direct suppliers and service providers, and Article 21(3) requires entities to take into account each direct supplier's specific vulnerabilities, the overall quality of its products and cybersecurity practices, and its secure development procedures; Article 22 adds coordinated EU-level risk assessments of critical supply chains. The GDPR requires processors to provide sufficient guarantees (Article 28(1)), a written data processing agreement (databehandleraftale) with the content listed in Article 28(3), and prior authorisation for sub-processors (Article 28(2)). DORA goes furthest for financial entities, with a register of information on all ICT third-party arrangements and mandatory contractual provisions. NIST CSF 2.0 places the topic in the Govern function as GV.SC.

Assurance comes in tiers: supplier questionnaires (self-assessments such as the CSA CAIQ or a customer's own), certificates (ISO/IEC 27001, checking that the scope actually covers the purchased service), independent assurance reports (ISAE 3402 or SOC 2 Type II covering a period of operation; in Denmark ISAE 3000 reports are common for data processors), and the customer's own audits. Technical signals such as external attack-surface ratings and SBOMs complement but do not replace them.

Common failure modes: tiering done once at onboarding and never revisited; contracts without breach-notification deadlines, audit rights or exit clauses; blind spots for fourth parties, such as a SaaS provider's own hosting and subcontractors; privileged remote access for suppliers without MFA, session logging or time limits; and trusting a certificate whose scope excludes the service actually used. Incidents such as the SolarWinds Orion compromise in 2020 and the MOVEit Transfer exploitation in 2023 showed how a single supplier can become the entry point to thousands of customers, which is why supplier management overlaps with software supply chain security rather than being a procurement formality.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Threat
  3. →Asset
  4. →Vulnerability
  5. →Impact
  6. →Likelihood
  7. →Risk
  8. →Supplier management

Relationships

Requires
Risk

Sources & further reading

Standards & official texts

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.