Question group
Third parties and subprocessors
The supplier's own suppliers: who else touches the customer's data, whether the customer is told before that changes, and how those suppliers are assessed.
The families
2 families| Family and a typical question | ISO 27001 | Evidence expected |
|---|---|---|
| Subcontractors and subprocessorsDo you use subcontractors to process our data? List them. | 5.19, 5.20, 5.21 | The list of subprocessors with what each does, where it processes and what data it reaches, the contract terms that flow down, and the notice route for changes. |
| Assessing your own suppliersHow do you assess the security of your own critical suppliers? | 5.22 | The supplier assessment procedure, the tiering of suppliers by the data they reach, and the last assessment record for each critical supplier. |