The heart of the problem
"But we have outsourced that to supplier X, and they are ISO 27001 certified!"
This is one of the most frequently heard responses during audits. It sounds logical, but it is a dangerous assumption. Your supplier's ISO 27001 certificate says something about how they manage their own risks, not how your risks are mitigated.
A familiar scenario
Many organisations outsource their technical management to an external party. That is understandable: not every SME has the knowledge or the capacity in house to manage servers, secure networks or arrange backups. Often this concerns controls from Annex A8 (Technological controls) of ISO 27001 or NEN 7510.
When selecting such a party, the requirement is then often set that "the supplier must be NEN 7510 or ISO 27001 certified." That is a perfectly good starting point. But too often that is where it stops. The customer assumes that this certification automatically means the technological controls have been implemented well enough. And that is a misconception with potentially major consequences.
What does an ISO 27001 certificate actually say?
An ISO 27001 certificate confirms that an organisation has a working Information Security Management System (ISMS) that meets the requirements of the standard. But there are a few crucial nuances:
The certificate is based on their risk assessment
The supplier has carried out a risk assessment from their own perspective. The controls they have implemented are geared to the risks they themselves consider relevant. That need not be in line with the risks your organisation wants or has to mitigate.
The scope may be limited
Every ISO 27001 certificate has a scope: a demarcation of which services and processes are certified. The services the supplier delivers to your organisation do not by definition fall within it. Always check the scope stated on the certificate.
A certificate is a snapshot in time
A certificate is assessed periodically, but it says something about the moment of the audit. In between audits, the quality of the service can change. Without monitoring of your own, you have no view of that.
The real problem: losing control
When you outsource, the execution of technological controls shifts to the supplier. But accountability always remains with your organisation. This is a fundamental principle of both ISO 27001 and NEN 7510.
In concrete terms this means: if a data breach occurs because your supplier did not have adequate backups, your organisation is liable, not the supplier. You can outsource the execution, but not the accountability.
The auditor's perspective
As an auditor, the question I ask is not "Is your supplier certified?" but "Which requirements have you set for your supplier? How do you check that they are being met? And what do you do if they are not?" It is not about the certificate, it is about staying in control.
So how do you get it right?
The customer must always be in the driving seat. In concrete terms, that means:
1. Set your own requirements
Before you outsource anything, you need to know what you want to outsource and which requirements you attach to it. Translate your own risk assessment into concrete requirements for the supplier. Think of:
Backup & restore
- Backup frequency
- Retention period
- Restore times (RTO/RPO)
- Periodic restore tests
Network security
- Firewall configuration
- Segmentation
- Monitoring and detection
- Patch management
Cryptography
- Encryption in transit and at rest
- Key management
- Certificate management
- Minimum encryption standards
Access management
- Who has access to what?
- Multi-factor authentication
- Logging of administrative access
- Periodic review of access rights
2. Set the arrangements down in a contract
Do not make verbal arrangements, but record everything in:
Service Level Agreement (SLA)
Concrete arrangements about availability, response times, performance indicators and escalation procedures.
Agreements and Procedures Document (DAP)
Detailed technical arrangements about how controls are implemented, who is responsible for what and how changes are carried through.
Data processing agreement
Mandatory under the GDPR when the supplier processes personal data. It contains arrangements about security, the notification obligation and sub-processors.
3. Monitor and verify
Making arrangements is step one. Checking whether they are being honoured is at least as important:
- Periodic reports: have the supplier report monthly or quarterly on the agreed performance indicators
- Evidence of restore tests: a backup you cannot restore is worthless. Require periodic restore tests with evidence
- Patch reports: which patches have been installed, which are still outstanding and why?
- Incident reports: have there been incidents that affect your environment?
- Periodic supplier assessment: evaluate at least once a year whether the supplier is meeting the arrangements
Practical overview: what do you need to arrange?
Common mistakes
Blind trust in the certificate
"They are certified, so it must be fine." Always check the scope, ask for the Statement of Applicability and set your own requirements.
No concrete arrangements
Without an SLA or a DAP there are no measurable arrangements. "They take care of the backups" is not the same as "daily backups with 30 days' retention and a monthly restore test".
Not monitoring
Making arrangements without checking them is like putting a lock on the door but never checking whether it is locked. Require reports and review them.
"Handing over" accountability
You can outsource the execution, but not the accountability. In an audit or an incident, you are the one who has to be able to demonstrate that you are in control.
Conclusion: stay in control
Outsourcing technical management is a perfectly good choice, certainly for SMEs. And setting the requirement that your supplier is ISO 27001 or NEN 7510 certified is a good first step. But it is no more than that: a first step.
The key is staying in control. Set your own requirements on the basis of your own risk assessment, record them in contracts and SLAs, and monitor whether they are being met. That is the only way your organisation can demonstrate that it really is "in control", regardless of whether the execution takes place internally or externally.
ComplianceGuard helps you stay in control
With the Supplier Management module in ComplianceGuard you manage all your suppliers, record arrangements and schedule periodic assessments. Combined with Risk Management, you always have insight into which risks you have outsourced and whether the mitigating controls are adequate.
On top of that, UDES Advies & Auditing can support you in drawing up a suitable set of requirements and in carrying out supplier assessments.