ExportableProof — Routines today. Proof tomorrow.

Policy

Supplier Relationships Policy

This document is Arcfield's Supplier Relationships Policy, document ID SUP-REL-POL-001. It binds supplier security classification, due diligence, contracting, monitoring, incidents and exit for suppliers that can affect Arcfield Platform confidentiality, integrity or availability. It is not the ISMS Scope Statement, the Risk Assessment Methodology or the Statement of Applicability. It applies to Arcfield Platform production, customer data, CI/CD, privileged access and critical suppliers. Neighbouring records cite this Document Control version. Do not copy these paragraphs into those records.

This file is a fictional Arcfield example, not your organization's approved policy. Copy this file as the controlled Word master for your ISMS only after you replace Arcfield decisions with your own.

Back to demo

OSCAL source · SRP

{
  "artifactId": "SRP",
  "iso": [
    "A.5.19",
    "A.5.20",
    "A.5.21",
    "A.5.22",
    "A.5.23"
  ],
  "catalog": [
    {
      "iso": "A.5.19",
      "oscalId": "iso27001-a.5.19",
      "title": "Information security in supplier relationships",
      "className": "iso27001-annex-a",
      "group": "Organizational controls (Annex A.5)"
    },
    {
      "iso": "A.5.20",
      "oscalId": "iso27001-a.5.20",
      "title": "Addressing information security within supplier agreements",
      "className": "iso27001-annex-a",
      "group": "Organizational controls (Annex A.5)"
    },
    {
      "iso": "A.5.21",
      "oscalId": "iso27001-a.5.21",
      "title": "Managing information security in the ICT supply chain",
      "className": "iso27001-annex-a",
      "group": "Organizational controls (Annex A.5)"
    },
    {
      "iso": "A.5.22",
      "oscalId": "iso27001-a.5.22",
      "title": "Monitoring, review and change management of supplier services",
      "className": "iso27001-annex-a",
      "group": "Organizational controls (Annex A.5)"
    },
    {
      "iso": "A.5.23",
      "oscalId": "iso27001-a.5.23",
      "title": "Information security for use of cloud services",
      "className": "iso27001-annex-a",
      "group": "Organizational controls (Annex A.5)"
    }
  ],
  "profileAlters": [
    {
      "control-id": "iso27001-a.5.19",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required for cloud and SaaS supplier dependencies."
            },
            {
              "name": "implementation-status",
              "value": "In progress"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-a.5.20",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required for supplier security terms."
            },
            {
              "name": "implementation-status",
              "value": "In progress"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-a.5.21",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required for SaaS, repository, identity and hosting chain."
            },
            {
              "name": "implementation-status",
              "value": "Planned"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-a.5.22",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required for supplier performance and changes."
            },
            {
              "name": "implementation-status",
              "value": "In progress"
            }
          ]
        }
      ]
    },
    {
      "control-id": "iso27001-a.5.23",
      "adds": [
        {
          "props": [
            {
              "name": "applicability",
              "value": "applicable"
            },
            {
              "name": "applicability-justification",
              "value": "Required because core services are cloud and SaaS based."
            },
            {
              "name": "implementation-status",
              "value": "In progress"
            }
          ]
        }
      ]
    }
  ],
  "components": [],
  "sspImplementedRequirements": []
}

Check installation

What is installed here. Extra volumes are optional and do not change Ready. Update re-runs the check.

CheckResult
Webserver…
Python…
Volumes…
Scripts…
Ready…
Working directory…
Last update…