A.5.21 Managing Information Security in the ICT Supply Chain
Control Objective
Processes and procedures shall be defined and implemented to manage the information security risks associated with the ICT products and services supply chain.
Policy Statement
anDREa manages supply chain risks through a structured lifecycle including pre-onboarding Security Impact Assessments (SIAs), contractually enforced security requirements, and continuous monitoring.
While anDREa actively enforces security standards (such as encryption and access control) across its supply chain, we recognize our size relative to hyperscale providers (e.g., global cloud platforms, banks). Where contract terms cannot be influenced, risks are mitigated through rigorous gap analyses and independent audit reviews.
Supply Chain Risk Management Process
1. Pre-Onboarding & Annual Assessments
Prior to onboarding, or during the annual supplier review, a SIA Instructions is conducted to evaluate a supplier's ability to maintain the confidentiality, integrity, and availability of anDREa data.
For large, non-negotiable standard agreements (e.g., Microsoft, Google):
- Mandatory Gap Analysis: Standard agreements are mapped against anDREa’s security requirements (see A.05.19 - Information security in supplier relationships) to identify compliance gaps, such as audit rights or incident notification timelines.
- Risk Evaluation & Acceptance: Identified gaps are evaluated via an SIA. If no alternative supplier exists, residual risks must be formally approved and signed off by the Management Team.
- Alternative Monitoring: Where direct auditing is impossible, anDREa validates ongoing compliance by reviewing independent audit reports (e.g., SOC 2 type II), security bulletins, and service health dashboards. All findings are logged in the Issues & Risk Log.
2. Cross-References & Policy Alignment
Supplier management principles are executed in alignment with:
- A.05.19 - Information security in supplier relationships
- A.05.20 - Addressing information security within supplier agreements
- A.05.22 - Monitoring, review and change management of supplier services
- A.05.23 - Information security for use of cloud services
3. Contractual Security Requirements
Where negotiation is possible, supplier contracts must incorporate standardized security clauses using the ARBIT. Contracts must clearly define roles, responsibilities, and non-compliance consequences regarding:
- Data protection and encryption standards
- Access control mechanisms
- Incident reporting timelines
4. Tiered Monitoring and Audits
anDREa adopts a tiered approach, classifying suppliers by risk level (e.g., critical vs. non-critical) to apply proportional controls:
- Critical Suppliers: Subject to periodic performance reviews, security certification validation (e.g., ISO/IEC 27001), and Service Level Agreement (SLA) verification (including uptime, patch management, and incident response metrics).
- Documentation: Review records are stored centrally within the anDREa Supplier List.
5. Incident Management
Suppliers must possess adequate capabilities to handle and report security incidents:
- All supply chain incidents follow A.06.08 - Information security event reporting.
- Where applicable, collaborative incident response plans are established to define communication protocols during a breach.
6. Security Awareness and Training
Employees responsible for procurement and vendor management receive specialized training to identify, assess, and monitor ICT supply chain risks.