A.5.22 Monitoring, Review, and Change Management of Supplier Services
Control Objective
The organization shall regularly monitor, review, evaluate and manage changes in supplier information security practices and service delivery.
Policy Statement
anDREa continuously monitors and evaluates supplier service delivery to ensure strict adherence to contractually agreed security terms, prompt incident resolution, and controlled management of all supply chain changes.
Supplier Monitoring and Review Process
anDREa actively validates supplier compliance and performance through the following mechanisms:
- Performance Monitoring: Service performance levels are monitored against agreed metrics (e.g., Microsoft Azure SLAs) to verify ongoing compliance.
- Incident Tracking: Supplier-related security incidents are tracked continuously. Suppliers are contractually required to provide immediate notification of any security events affecting anDREa.
- Audit & Remediation: Where applicable, anDREa reviews independent third-party audit reports (e.g., SOC 2 type II) or conducts direct audits. Any identified issues are tracked through to resolution.
- Dispute Resolution: Suppliers must maintain a formal conflict resolution process to handle unmet security requirements. This capability is verified during pre-onboarding Security Impact Assessments (SIAs, see SIA Instructions) and subsequent reviews.
Review Frequencies
Suppliers are reviewed based on their risk profile, with specific frequencies defined in the anDREa Supplier List:
- Critical & High-Risk Suppliers: Reviewed annually, or ad-hoc when significant operational or architecture changes occur.
- Standard Ecosystem Suppliers: Reviewed annually.
Managing Changes in Supplier Services
To maintain a consistent security posture, any modification to the supplier ecosystem must be evaluated. The following triggers require a formal review:
1. Changes Initiated by the Supplier
- Modifications to the supplier agreement or terms of service.
- Infrastructure changes (e.g., network enhancements, new development tools/environments).
- Technology lifecycle updates (e.g., adoption of new products, versions, or releases).
- Relocation of physical service facilities.
- Sub-contracting or outsourcing services to a third party.
2. Changes Initiated by anDREa
- Enhancements to existing services or development of new applications and systems.
- Policy updates that require operational alignment from suppliers.
- Newly implemented controls designed to mitigate security incidents.