ISO/IEC 27001:2022
Rendered when "ISO/IEC 27001:2022 (yours)" is ticked and the customer reaches it. The register cites 8 of its 93 clauses, behind 7 findings: breach-notice clocks that disagree, personal data with no dpa shown, audit rights granted, renewal inside 90 days, notice window already missed or inside 30 days, duplicate agreement, no owner, and on the rows it reaches.
Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so. Source framework: ISO/IEC 27001:2022. What it expects of an agreement: the ISO 27001 regime page.
Clauses cited
8 of 93ISO 27001 A.5.19 Information security in supplier relationshipsDefine and apply processes to manage the security risk suppliers introduce.
Where it usually falls short: Treating all suppliers as low risk
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.20 Addressing information security within supplier agreementsEstablish and agree the relevant security requirements in each supplier contract.
Where it usually falls short: missing explicit security clauses
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.21 Managing information security in the ICT supply chainExtend security requirements down the ICT products and services supply chain.
Where it usually falls short: Treating supplier security as one-off check
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.23 Information security for use of cloud servicesGovern acquisition, use, management and exit of cloud services against your security requirements.
Where it usually falls short: Relying solely on provider's security assurances
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.24 Information security incident management planning and preparationDefine incident roles, processes and readiness before an incident happens.
Where it usually falls short: roles are defined but not formally assigned or approved
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.31 Legal, statutory, regulatory and contractual requirementsIdentify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.
Where it usually falls short: outdated legal register
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.34 Privacy and protection of personal identifiable information (PII)Identify and meet privacy and PII-protection requirements from law, regulation and contract.
Where it usually falls short: Missing documented consent for all data subjects
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.6.6 Confidentiality or non-disclosure agreementsIdentify, document, review and sign NDAs that reflect the organization's protection needs.
Where it usually falls short: NDAs not refreshed when data classification changes
ISO/IEC 27001:2022 in The Art of Service standards library
See which clauses your list engages
Paste the list of customer agreements and every row names the clauses behind it. Eight agreements free, no account.
Check my contract list