ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Supplier Security Addendum

Supplier Security Addendum

1. Purpose

This Supplier Security Addendum (“Addendum”) establishes the information-security requirements applicable to the services provided by the Supplier to [Organization Name] (“Organization”).

This Addendum is intended to protect the Organization’s information, systems, applications, customer information, personal data, confidential information, and business operations from unauthorized access, disclosure, alteration, loss, misuse, or disruption.

This Addendum forms part of the applicable agreement between the Organization and the Supplier.


2. Scope

This Addendum applies to the Supplier and, where applicable, its:

  • Employees
  • Contractors
  • Consultants
  • Subcontractors
  • Subprocessors
  • Affiliates
  • Service providers
  • Other third parties involved in delivering the Services

The requirements apply to information and systems that the Supplier accesses, processes, stores, transmits, hosts, or otherwise handles on behalf of the Organization.

The specific requirements applicable to the Supplier should be determined based on the nature of the Services, information handled, access provided, supplier criticality, risk assessment, legal requirements, and contractual obligations.


3. Definitions

For this Addendum:

Organization means [Organization Name].

Supplier means [Supplier Legal Name].

Services means the products, services, technology, support, or other activities provided by the Supplier under the applicable agreement.

Organization Information means information provided by or on behalf of the Organization, or generated or processed for the Organization in connection with the Services.

Confidential Information means information classified as confidential by the Organization or information that should reasonably be understood to require protection.

Security Incident means an event that has compromised or may compromise the confidentiality, integrity, or availability of information or systems relevant to the Services.

Personal Data means information relating to an identified or identifiable individual, as defined by applicable law.

Subprocessor/Subcontractor means a third party engaged by the Supplier to process information or perform material activities related to the Services.


4. General Security Obligations

The Supplier shall maintain security controls appropriate to the nature and risk of the Services.

The Supplier shall:

  1. Protect Organization Information against unauthorized access, disclosure, alteration, loss, destruction, or misuse.
  2. Maintain appropriate administrative, technical, and physical security controls.
  3. Restrict access to authorized personnel.
  4. Apply least-privilege and need-to-know principles.
  5. Maintain security controls appropriate to the sensitivity of information processed.
  6. Comply with applicable contractual, legal, regulatory, and security requirements.
  7. Maintain appropriate security policies and procedures.
  8. Notify the Organization of material security events affecting the Services.
  9. Cooperate with reasonable security investigations.
  10. Maintain appropriate controls throughout the supplier relationship.

5. Information Classification and Handling

The Supplier shall handle Organization Information according to the classification and handling instructions communicated by the Organization.

The Supplier shall:

  • Use information only for authorized business purposes.
  • Restrict access to authorized personnel.
  • Avoid unnecessary copying or duplication.
  • Protect confidential and restricted information.
  • Use approved methods for transferring sensitive information.
  • Prevent unauthorized disclosure.
  • Maintain appropriate records where required.
  • Securely dispose of information when no longer required and when permitted by applicable retention obligations.

The Organization may use classifications such as Public, Internal, Confidential, and Restricted. The applicable classification scheme shall be communicated to the Supplier.


6. Access Control

Supplier access to Organization systems and information shall be limited to what is necessary to perform the Services.

The Supplier shall:

  • Use individually identifiable accounts where practical.
  • Restrict access based on business need.
  • Apply least privilege.
  • Prevent unauthorized account sharing.
  • Review access periodically.
  • Remove access when no longer required.
  • Promptly remove access when personnel leave the Supplier or no longer require access.
  • Protect authentication credentials.
  • Maintain appropriate controls over privileged access.

The Supplier shall not attempt to access systems, information, or environments outside the authorized scope.


7. Authentication and Multi-Factor Authentication

Where the Supplier or its personnel access Organization systems:

  • Strong authentication shall be used.
  • Multi-factor authentication (“MFA”) shall be implemented where required by the Organization.
  • MFA shall be required for privileged access where technically supported.
  • Credentials shall not be shared.
  • Default credentials shall be changed.
  • Compromised credentials shall be reported promptly.
  • Authentication information shall be securely stored.

8. Privileged Access

Where privileged or administrative access is required:

  • Privileged access shall be separately authorized.
  • Access shall be limited to designated personnel.
  • Privileged accounts shall be individually attributable where practical.
  • Privileged activities shall be logged where technically feasible.
  • Privileged access shall be periodically reviewed.
  • Temporary privileges should have defined expiration where appropriate.
  • Privileged access shall be removed when no longer required.

The Supplier shall not retain administrative access after completion of the Services unless specifically authorized.


9. Remote Access

Where remote access to Organization systems is permitted:

  • Access shall be authorized.
  • Appropriate authentication shall be implemented.
  • MFA shall be used where required.
  • Secure communication channels shall be used.
  • Access shall be limited to approved systems.
  • Remote access shall be monitored where appropriate.
  • Unnecessary remote-access mechanisms shall be disabled.
  • Remote access shall be revoked when no longer required.

10. Personnel Security

The Supplier shall maintain personnel-security practices appropriate to the nature of the Services.

Where appropriate and legally permitted, the Supplier shall:

  • Conduct appropriate personnel screening.
  • Maintain confidentiality obligations.
  • Provide security awareness training.
  • Communicate relevant security responsibilities.
  • Restrict access based on job responsibilities.
  • Remove access when personnel leave or change responsibilities.
  • Apply appropriate disciplinary processes for security violations.

11. Security Awareness

Supplier personnel with access to Organization Information or systems shall receive appropriate security awareness and role-based training.

Training should address, as applicable:

  • Information protection
  • Password and authentication security
  • Phishing and social engineering
  • Data handling
  • Incident reporting
  • Privacy
  • Acceptable use
  • Secure remote working
  • Handling of confidential information

12. Endpoint Security

Supplier endpoints used to access Organization systems shall maintain appropriate security controls.

Where applicable, the Supplier shall implement:

  • Supported operating systems
  • Security updates
  • Endpoint protection
  • Host firewall
  • Disk encryption
  • Screen-lock controls
  • Malware protection
  • Secure configuration
  • Protection against unauthorized software
  • Secure disposal or wiping of devices

13. Network Security

Where the Services involve network connectivity, the Supplier shall maintain appropriate network-security controls, including where applicable:

  • Network segmentation
  • Firewall controls
  • Secure communication protocols
  • Access restrictions
  • Secure remote connectivity
  • Network monitoring
  • Protection against unauthorized connections
  • Periodic review of network access

14. Cloud Security

Where cloud infrastructure is used to provide the Services, the Supplier shall maintain appropriate cloud-security controls.

Depending on the Services, these may include:

  • Identity and access management
  • MFA
  • Least privilege
  • Privileged access management
  • Security logging
  • Encryption
  • Secure configuration
  • Vulnerability management
  • Backup and recovery
  • Security monitoring
  • Data-location controls
  • Subprocessor management

Where the Supplier operates within the Organization’s cloud environment, the Supplier shall comply with the Organization’s applicable cloud-security requirements.


15. Application Security

Where the Supplier develops, maintains, or operates applications for the Organization, the Supplier shall maintain security practices appropriate to the application.

These may include:

  • Secure development practices
  • Security requirements
  • Code review
  • Dependency management
  • Vulnerability management
  • Security testing
  • Change control
  • Environment segregation
  • Secure configuration
  • Secrets management
  • Secure release processes

Security vulnerabilities identified in the Services shall be risk-assessed and addressed within reasonable timeframes based on severity.


16. Vulnerability Management

The Supplier shall maintain a vulnerability-management process appropriate to the Services.

The process should include:

  • Identification of vulnerabilities
  • Risk assessment
  • Prioritization
  • Remediation
  • Security patching
  • Verification
  • Tracking of unresolved vulnerabilities

Critical or significant vulnerabilities that could materially affect Organization Information or Services shall be communicated to the Organization where appropriate.


17. Security Testing

Where appropriate based on risk and service type, the Supplier shall perform security testing such as:

  • Vulnerability assessments
  • Penetration testing
  • Application security testing
  • Configuration assessments
  • Security reviews

The Organization may request reasonable evidence of relevant security testing, subject to confidentiality and security restrictions.


18. Encryption

The Supplier shall implement encryption appropriate to the sensitivity of information and the risks involved.

Where applicable:

Data in Transit

Sensitive information shall be transmitted using appropriately secured communication channels.

Data at Rest

Sensitive information shall be encrypted where required by risk, contract, law, regulation, or the Organization’s security requirements.

Encryption keys shall be protected against unauthorized access.


19. Secrets and Credentials

The Supplier shall protect passwords, API keys, tokens, certificates, encryption keys, and other secrets.

The Supplier shall:

  • Restrict access to secrets.
  • Avoid storing secrets in source code.
  • Avoid transmitting secrets through unsecured channels.
  • Rotate credentials where appropriate.
  • Revoke compromised credentials promptly.
  • Remove Organization credentials when no longer required.

20. Logging and Monitoring

The Supplier shall maintain security logging appropriate to the Services.

Where applicable, logs should include:

  • Authentication events
  • Privileged activities
  • Administrative actions
  • Security events
  • Material configuration changes
  • Relevant application events

The Supplier shall protect logs against unauthorized modification and retain them for an appropriate period.

Where contractually required and legally permitted, relevant security records may be made available to the Organization.


21. Security Incident Management

The Supplier shall maintain an incident-management process capable of identifying, responding to, containing, investigating, and recovering from security incidents.

The Supplier shall:

  • Identify and investigate security incidents.
  • Take reasonable containment measures.
  • Preserve relevant evidence.
  • Implement corrective actions.
  • Cooperate with the Organization where an incident affects the Organization or the Services.

22. Security Incident Notification

The Supplier shall notify the Organization of a Security Incident that materially affects or may materially affect:

  • Organization Information
  • Personal Data
  • Customer Data
  • Organization systems
  • Confidentiality
  • Integrity
  • Availability
  • Security of the Services

Security Incident Contact:

Name: __________________________

Email: __________________________

Phone: __________________________

Required Notification Timeframe: __________________________

The applicable notification timeframe shall be determined by the contract, applicable law, regulatory requirements, customer commitments, and risk.

Initial notification should include, to the extent known:

  • Date/time of incident
  • Nature of incident
  • Affected systems/services
  • Information potentially affected
  • Known or suspected impact
  • Containment actions
  • Current status
  • Supplier incident contact

The Supplier shall provide reasonable updates as material information becomes available.


23. Data Breach

Where Personal Data or Customer Data is involved in a Security Incident:

The Supplier shall:

  • Promptly notify the Organization according to the agreed requirements.
  • Cooperate with investigation and response activities.
  • Preserve relevant evidence.
  • Provide reasonably available information needed for assessment.
  • Support applicable notification obligations.
  • Implement corrective actions.
  • Prevent recurrence where reasonably possible.

The Supplier shall not make external notifications specifically concerning the Organization or its customers without coordinating with the Organization where legally permitted, except where independent notification is required by law.


24. Privacy and Personal Data

Where the Supplier processes Personal Data:

  • Processing shall be limited to authorized purposes.
  • Access shall be restricted.
  • Appropriate security measures shall be implemented.
  • Retention shall be controlled.
  • Applicable data-protection requirements shall be followed.
  • Data breaches shall be reported as required.
  • Subprocessors shall be appropriately controlled.
  • Data-return/deletion obligations shall be followed.
  • Cross-border processing requirements shall be addressed where applicable.

Where required, the parties shall execute a separate Data Processing Agreement (DPA).


25. Subcontractors and Subprocessors

The Supplier shall maintain appropriate oversight of subcontractors and subprocessors involved in providing the Services.

The Supplier shall:

  • Identify relevant subcontractors/subprocessors.
  • Ensure applicable security obligations flow down to them.
  • Remain responsible for their performance to the extent provided by the applicable contract and law.
  • Notify the Organization of material changes where contractually required.
  • Obtain Organization approval where expressly required by the contract.
  • Assess security risks associated with relevant subcontractors.

26. Data Location

Where relevant, the Supplier shall maintain information regarding:

  • Data storage locations
  • Data processing locations
  • Hosting locations
  • Relevant subprocessors
  • Cross-border transfers

Material changes to agreed data locations shall be communicated to the Organization where contractually required.


27. Backup and Recovery

Where the Supplier stores or manages Organization Information or provides critical Services:

  • Appropriate backup controls shall be maintained.
  • Backups shall be protected against unauthorized access.
  • Backup restoration shall be tested where appropriate.
  • Recovery procedures shall be maintained.
  • Recovery objectives shall be established where applicable.
  • Critical service dependencies shall be identified.

28. Business Continuity and Disaster Recovery

For critical or important Services, the Supplier shall maintain appropriate business continuity and disaster-recovery arrangements.

Where applicable:

  • Recovery procedures shall be documented.
  • Relevant personnel shall understand their responsibilities.
  • Recovery capabilities shall be tested periodically.
  • Material continuity risks shall be identified.
  • Significant changes to continuity arrangements shall be communicated.
  • Recovery objectives shall align with agreed service requirements.

29. Information Transfer

The Supplier shall use appropriately secured methods when transferring Organization Information.

The Supplier shall:

  • Use approved transfer mechanisms where specified.
  • Protect sensitive information during transmission.
  • Verify recipients where appropriate.
  • Avoid unauthorized communication channels.
  • Minimize unnecessary copies.
  • Maintain transfer records where required.

30. Physical Security

Where Supplier facilities are used to process or store Organization Information or operate relevant systems, the Supplier shall maintain appropriate physical-security controls.

These may include:

  • Physical access controls
  • Visitor management
  • Secure areas
  • Equipment protection
  • Environmental controls
  • Secure media storage
  • Secure disposal

31. Security Assurance

Depending on supplier risk, the Supplier may be required to provide reasonable evidence of its security controls.

Acceptable evidence may include:

  • ISO 27001 certification
  • SOC reports
  • Independent audit reports
  • Security assessment reports
  • Penetration-test summaries
  • Vulnerability-management evidence
  • Business continuity evidence
  • Security policies
  • Completed security questionnaires

The specific assurance requirements shall be agreed based on the Supplier’s risk and Services.


32. Security Assessments and Audit Rights

Where justified by risk and agreed in the contract, the Organization may assess the Supplier’s compliance with applicable security requirements.

Assessment mechanisms may include:

  • Security questionnaires
  • Document/evidence review
  • Independent assurance reports
  • Remote assessments
  • Security reviews
  • On-site assessments where reasonably necessary

The Organization shall use reasonable efforts to avoid unnecessary disruption to the Supplier’s operations.

Any assessment shall remain subject to applicable confidentiality, security, legal, and contractual restrictions.


33. Security Findings and Remediation

Where a security assessment identifies a significant deficiency:

  1. The issue shall be documented.
  2. Risk shall be assessed.
  3. Corrective action shall be agreed where appropriate.
  4. An owner shall be identified.
  5. A target completion date shall be established.
  6. Remediation shall be tracked.
  7. Closure evidence shall be obtained where appropriate.

For significant unresolved risks, the parties may agree on:

  • Compensating controls
  • Temporary risk acceptance
  • Enhanced monitoring
  • Remediation plans
  • Service restrictions
  • Other appropriate measures

34. Material Security Changes

The Supplier shall notify the Organization of material changes that may affect the security of the Services where such notification is required by the contract.

Examples include:

  • Material change in ownership
  • Major change in hosting environment
  • Significant change in data location
  • New critical subprocessor
  • Major security incident
  • Significant change in security architecture
  • Material change in access model
  • Significant service disruption
  • Material regulatory or compliance issue

35. Security Cooperation

The Supplier shall provide reasonable cooperation in relation to:

  • Security incidents
  • Data breaches
  • Vulnerability investigations
  • Customer security inquiries
  • Regulatory inquiries relating to the Services
  • Security assessments
  • Business continuity events
  • Evidence requests
  • Corrective actions

Such cooperation shall be subject to applicable law, confidentiality obligations, and the terms of the applicable agreement.


36. Intellectual Property and Organization Information

The Supplier shall not use Organization Information, source code, documentation, credentials, or other assets for purposes outside the authorized Services.

Unless expressly authorized:

  • Organization Information shall not be sold.
  • Organization Information shall not be disclosed to unauthorized parties.
  • Organization Information shall not be used for unrelated commercial purposes.
  • Source code shall not be reused outside the authorized scope.
  • Credentials shall not be transferred to unauthorized parties.

37. Use of Organization Information for AI/Generative AI

Unless expressly authorized by the Organization, the Supplier shall not submit Organization Confidential, Restricted, Customer, or Personal Data to public or third-party AI/Generative AI services for training, analysis, or other processing unrelated to the Services.

Where AI/Generative AI is used in delivering the Services:

  • Applicable AI use shall be disclosed where required.
  • Information submitted to AI services shall be appropriately controlled.
  • Confidential information shall not be exposed to unauthorized AI services.
  • Applicable security and privacy requirements shall be maintained.
  • Relevant subprocessors or AI providers shall be identified where required.

38. Regulatory and Legal Requirements

The Supplier shall comply with applicable laws and regulations relevant to the Services and information processed.

Depending on the relationship, these may include requirements relating to:

  • Information security
  • Privacy
  • Data protection
  • Financial services
  • Healthcare
  • Payment processing
  • Employment data
  • Records retention
  • Cross-border data transfers

The parties shall identify specific regulatory requirements applicable to the Services.


39. Service Availability

Where availability is important to the Services:

  • Availability requirements shall be defined in the applicable agreement/SLA.
  • Significant outages shall be communicated.
  • Recovery arrangements shall be maintained.
  • Service continuity requirements shall be documented.
  • Major availability incidents shall be investigated where appropriate.

Applicable SLA: __________________________


40. Supplier Monitoring and Review

The Organization may periodically review the Supplier based on risk.

Review activities may include:

  • Security questionnaire
  • Certification review
  • Assurance-report review
  • Incident review
  • Vulnerability review
  • Access review
  • Subprocessor review
  • Data-location review
  • BCP/DR review
  • Contract compliance review
  • Security assessment

The frequency shall be based on supplier criticality and risk.


41. Security Requirements Matrix

The following matrix should be completed for the specific Supplier.

RequirementApplicableMandatoryEvidenceContractual
Confidentiality
Access Control
MFA
Privileged Access
Encryption
Vulnerability Management
Security Testing
Logging & Monitoring
Incident Notification
Data Breach
Privacy
Subprocessors
Data Location
Backup
Business Continuity
Audit/Assurance
Secure Offboarding

42. Supplier Responsibilities

The Supplier shall designate appropriate personnel responsible for meeting the applicable security requirements.

Supplier Security Contact

Name: __________________________

Title: __________________________

Email: __________________________

Phone: __________________________

Supplier Business Contact

Name: __________________________

Email: __________________________

Phone: __________________________


43. Organization Responsibilities

The Organization shall:

  • Communicate applicable security requirements.
  • Identify relevant information classifications.
  • Approve Supplier access where required.
  • Provide reasonable security information necessary for the Supplier to perform the Services.
  • Notify the Supplier of material security requirements relevant to the Services.
  • Coordinate security incidents involving the Organization and Supplier as appropriate.

44. Security Requirement Exceptions

Any exception to this Addendum shall be:

  • Documented.
  • Risk-assessed.
  • Approved by an authorized Organization representative.
  • Time-bound where appropriate.
  • Supported by compensating controls where necessary.

Exception Record

ExceptionReasonRiskCompensating ControlExpiryApproved By

45. Supplier Offboarding

Upon termination or expiration of the Services, the Supplier shall, as applicable:

  • Revoke Supplier personnel access.
  • Return Organization assets.
  • Return or securely delete Organization Information.
  • Disable technical connections.
  • Revoke credentials and tokens.
  • Remove Organization data from Supplier systems, subject to applicable retention obligations.
  • Address applicable backup copies according to agreed retention requirements.
  • Return or delete source code and documentation as required.
  • Provide reasonable confirmation of completion where required.
  • Continue to comply with confidentiality obligations that survive termination.

46. Security Requirements After Termination

Security obligations that are intended to survive termination, including confidentiality, data protection, information return/deletion, and relevant investigation/cooperation obligations, shall continue for the period specified in the applicable agreement or required by law.


47. Order of Precedence

This Addendum shall be read together with the applicable agreement, SOW, DPA, SLA, and other contractual documents.

Recommended precedence statement:

In the event of a conflict between this Addendum and another contractual document, the parties shall apply the order of precedence expressly defined in the applicable agreement.

Where a DPA or applicable law establishes specific privacy or data-protection requirements, those requirements shall apply to the extent required by law.


48. Confidentiality

Information exchanged during security assessments, audits, incident investigations, or compliance activities shall be handled in accordance with applicable confidentiality obligations.

The parties shall take reasonable measures to prevent unauthorized disclosure of security-sensitive information.


49. Acknowledgement and Acceptance

By signing below, the parties acknowledge that they have reviewed and accepted the applicable security requirements contained in this Addendum.

Organization

Legal Name: __________________________

Authorized Representative: __________________________

Title: __________________________

Signature: __________________________

Date: __________________________


Supplier

Legal Name: __________________________

Authorized Representative: __________________________

Title: __________________________

Signature: __________________________

Date: __________________________


50. Appendix A — Supplier Security Profile

ItemSupplier Response
Service Provided
Information Processed
Information Classification
Personal Data
Customer Data
Production Access
Privileged Access
Cloud Services
Data Locations
Subprocessors
Security Certification
SOC/Assurance Report
Security Testing
BCP/DR
Incident Contact
Security Contact
Review Frequency
Supplier Risk Rating
Critical SupplierYes / No

51. Appendix B — Security Evidence Register

EvidenceDateScopeValid UntilReviewed ByStatus
ISO 27001 Certificate
SOC Report
Penetration Test
Security Questionnaire
BCP/DR Evidence
Security Assessment
Other

52. Appendix C — Security Incident Contacts

Organization

Name: __________________________

Email: __________________________

Phone: __________________________

Supplier

Name: __________________________

Email: __________________________

Phone: __________________________

Escalation Contact

Name: __________________________

Email: __________________________

Phone: __________________________


53. ISO 27001 Alignment

This Supplier Security Addendum supports an organization’s broader information-security management and supplier-risk processes, including requirements relating to:

  • Supplier relationships
  • Security requirements in supplier agreements
  • ICT supply-chain security
  • Access control
  • Information transfer
  • Incident management
  • Business continuity
  • Information protection
  • Risk treatment
  • Supplier monitoring and review
  • Secure termination of supplier relationships

The Addendum itself is not a universally mandatory ISO 27001 document. The organization should determine which requirements apply based on its ISMS scope, risk assessment, Statement of Applicability, supplier criticality, contractual obligations, legal requirements, and business needs.


54. Final Audit Trail

An auditor should be able to trace:

Supplier
↓
Service
↓
Information
↓
Access
↓
Risk Assessment
↓
Applicable Security Requirements
↓
Contract / Addendum
↓
Security Controls
↓
Evidence
↓
Monitoring
↓
Security Review
↓
Incident / Corrective Action
↓
Offboarding

Final Principle

A Supplier Security Addendum should convert the organization’s security expectations into clear, agreed, and auditable obligations that are proportionate to the supplier’s actual risk.

It should answer four practical questions:

  1. What information or systems can the supplier access?
  2. What security controls must the supplier maintain?
  3. What must the supplier do when something goes wrong?
  4. What happens to access and information when the relationship ends?

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *