Regulated Customer Contract Checker
Standards ยท ISO 27001

ISO/IEC 27001:2022

Rendered when "ISO/IEC 27001:2022 (yours)" is ticked and the customer reaches it. The register cites 8 of its 93 clauses, behind 7 findings: breach-notice clocks that disagree, personal data with no dpa shown, audit rights granted, renewal inside 90 days, notice window already missed or inside 30 days, duplicate agreement, no owner, and on the rows it reaches.

Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so. Source framework: ISO/IEC 27001:2022. What it expects of an agreement: the ISO 27001 regime page.

Clauses cited

8 of 93
ISO 27001 A.5.19 Information security in supplier relationships

Define and apply processes to manage the security risk suppliers introduce.

Evidence an auditor accepts: Supplier risk assessment; Contractual security requirements; Supplier security monitoring
Where it usually falls short: Treating all suppliers as low risk
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.20 Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

Evidence an auditor accepts: Contract security clauses; Supplier risk assessment; Security incident reporting
Where it usually falls short: missing explicit security clauses
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.21 Managing information security in the ICT supply chain

Extend security requirements down the ICT products and services supply chain.

Evidence an auditor accepts: Supplier security requirements; Contractual security clauses; Supply chain risk assessments
Where it usually falls short: Treating supplier security as one-off check
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.23 Information security for use of cloud services

Govern acquisition, use, management and exit of cloud services against your security requirements.

Evidence an auditor accepts: Cloud service selection; Cloud contract management; Cloud security monitoring
Where it usually falls short: Relying solely on provider's security assurances
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.24 Information security incident management planning and preparation

Define incident roles, processes and readiness before an incident happens.

Evidence an auditor accepts: Incident response plan; Role assignment matrix; Training and awareness records
Where it usually falls short: roles are defined but not formally assigned or approved
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.31 Legal, statutory, regulatory and contractual requirements

Identify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.

Evidence an auditor accepts: Legal register; Contractual obligations; Regulatory filing records
Where it usually falls short: outdated legal register
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.34 Privacy and protection of personal identifiable information (PII)

Identify and meet privacy and PII-protection requirements from law, regulation and contract.

Evidence an auditor accepts: Privacy policy; Data inventory; Processing agreements
Where it usually falls short: Missing documented consent for all data subjects
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.6.6 Confidentiality or non-disclosure agreements

Identify, document, review and sign NDAs that reflect the organization's protection needs.

Evidence an auditor accepts: Nda policy; Nda templates; Signed nda registry
Where it usually falls short: NDAs not refreshed when data classification changes
ISO/IEC 27001:2022 in The Art of Service standards library

See which clauses your list engages

Paste the list of customer agreements and every row names the clauses behind it. Eight agreements free, no account.

Check my contract list