logo

Meeting the Third-Party Risk Requirements of ISO 27001 in 2024 | UpGuard

ID: 12aa8212-b646-535a-9be0-c6db99bd30ab

STIX ID: report--12aa8212-b646-535a-9be0-c6db99bd30ab

Feed Name: UpGuard Blog

Date Published: 2024-01-19

Date Updated: 2026-05-01

...
...

This guide explains how ISO/IEC 27001:2022 addresses third‑party risk management, summarizing key Organizational controls—5.9 (asset inventory), 5.19 (supplier relationship security), 5.20 (security in supplier agreements), 5.21 (ICT supply chain risk), and 5.22 (supplier monitoring and change management)—and outlines practices like risk assessments, access control, incident response, contract clauses, and continuous oversight; it also describes how UpGuard’s Attack Surface Management, Security Ratings, and Trust Exchange can support alignment and ongoing monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.