N.1.18 Monitoring, evaluation and change management of supplier services
Control Overview
This control mandates that the organization establishes a risk-based framework to continuously monitor and evaluate active suppliers. Rather than relying solely on pre-onboarding checks, the organization must dynamically adjust its oversight based on vendor criticality. This requires tracking ongoing service performance, reviewing security posture shifts (such as reviewing updated SOC 2 reports), managing changes in vendor services (e.g., changes in infrastructure, sub-contractors, or hosting locations), and taking corrective actions if a supplier falls short of agreed-upon security standards.
Applicability Note: This control is fully applicable to the anDREa platform and governs the ongoing oversight of all active critical infrastructure and software dependencies.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, moving away from static checklist reviews toward an active, risk-proportional monitoring model.
anDREa enforces a tier-based review cadence driven entirely by vendor criticality. While low-risk utilities follow an extended lifecycle, high-criticality suppliers are subjected to comprehensive annual reviews. This process evaluates technical reliability, security incident history, and compliance updates. Crucially, any operational or technical changes initiated by a supplier—such as rolling out new capabilities, modifying data center regions, or onboarding new sub-processors—must be formally logged and triaged via our internal change management ticketing system to guarantee our security baseline is never degraded.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.05.22 - Monitoring, review and change management of supplier services | Mandates regular monitoring, review, and auditing of supplier service delivery against agreed information security terms. |
| Operational Governance | Risk-Based Supplier Review Cadence | Framework text defining review cycles (e.g., annual vs. triennial) based on vendor data access and criticality. |
| Vendor Portfolios | Active Supplier Dossiers | Documented performance logs, audit summaries, updated certification tracking, and past security incident histories. (anDREa Supplier List) |
| Change Management | Supplier Change Tracking Tickets | The formal IT ticketing registry where vendor infrastructure changes or sub-processor updates are reviewed, risk-assessed, and approved. (Issues and Risk Logging) |
| Continuous Assurance | Periodic Controls Security Logs | Operational verification data confirming that third-party integrations continue to behave within baseline security parameters. (anDREa Supplier List) |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Criticality-based review cadences, change management ticketing workflows, and corrective tracking protocols are fully operationalized. Continuous Improvement: Explicitly incorporating NIS 2 terminology like "essential dependency" directly into the vendor directory will further ease alignment for upcoming regulatory audits, though it does not represent a functional gap.