Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Business Manager

previous version on gdrive

A.5.21 Managing Information Security in the ICT Supply Chain

Control Objective

Processes and procedures shall be defined and implemented to manage the information security risks associated with the ICT products and services supply chain.

Policy Statement

anDREa manages supply chain risks through a structured lifecycle including pre-onboarding Security Impact Assessments (SIAs), contractually enforced security requirements, and continuous monitoring.

While anDREa actively enforces security standards (such as encryption and access control) across its supply chain, we recognize our size relative to hyperscale providers (e.g., global cloud platforms, banks). Where contract terms cannot be influenced, risks are mitigated through rigorous gap analyses and independent audit reviews.


Supply Chain Risk Management Process

1. Pre-Onboarding & Annual Assessments

Prior to onboarding, or during the annual supplier review, a SIA Instructions is conducted to evaluate a supplier's ability to maintain the confidentiality, integrity, and availability of anDREa data.

For large, non-negotiable standard agreements (e.g., Microsoft, Google):

  • Mandatory Gap Analysis: Standard agreements are mapped against anDREa’s security requirements (see A.05.19 - Information security in supplier relationships) to identify compliance gaps, such as audit rights or incident notification timelines.
  • Risk Evaluation & Acceptance: Identified gaps are evaluated via an SIA. If no alternative supplier exists, residual risks must be formally approved and signed off by the Management Team.
  • Alternative Monitoring: Where direct auditing is impossible, anDREa validates ongoing compliance by reviewing independent audit reports (e.g., SOC 2 type II), security bulletins, and service health dashboards. All findings are logged in the Issues & Risk Log.

2. Cross-References & Policy Alignment

Supplier management principles are executed in alignment with:

3. Contractual Security Requirements

Where negotiation is possible, supplier contracts must incorporate standardized security clauses using the ARBIT. Contracts must clearly define roles, responsibilities, and non-compliance consequences regarding:

  • Data protection and encryption standards
  • Access control mechanisms
  • Incident reporting timelines

4. Tiered Monitoring and Audits

anDREa adopts a tiered approach, classifying suppliers by risk level (e.g., critical vs. non-critical) to apply proportional controls:

  • Critical Suppliers: Subject to periodic performance reviews, security certification validation (e.g., ISO/IEC 27001), and Service Level Agreement (SLA) verification (including uptime, patch management, and incident response metrics).
  • Documentation: Review records are stored centrally within the anDREa Supplier List.

5. Incident Management

Suppliers must possess adequate capabilities to handle and report security incidents:

6. Security Awareness and Training

Employees responsible for procurement and vendor management receive specialized training to identify, assess, and monitor ICT supply chain risks.