5Security operations & supplier management
- 5.1Security operations
Covers the operational controls that keep information security running in live service delivery-priority judgment for patch management and vulnerability management, log collection and monitoring, the SIEM that correlates multiple logs, and the handoff that connects detected incidents into incident management-framed as the judgments of an operator upholding SLA targets.
- 5.2Access management & privileged access
Covers access management, which controls who is allowed what in service operations-the principle of least privilege, the provisioning (granting) and periodic review (revocation) of privileges, privileged access management that handles powerful rights strictly, and the authentication that verifies identity-framed as an operator's judgment to prevent risks such as insider misuse and dangling leaver accounts.
- 5.3Supplier management & underpinning contracts
Covers supplier management, which aligns externally dependent parts with the SLA-the UC (underpinning contract) with external suppliers, aligning the customer SLA with UCs/OLAs, supplier evaluation and review, the demarcation of responsibility during faults, and the shared responsibility model when using the cloud-framed as the judgment of a service manager who ultimately upholds the SLA target.
- 5.4Service audit, corrective action & continual improvement
Covers the mechanisms that keep service management running and improving-the internal audit that detects nonconformities, the corrective action for findings (a permanent fix to the root cause, not a stopgap), CSI (continual service improvement), the PDCA cycle, and the KPIs/metrics that steer improvement by the numbers-framed as the judgment of a service manager improving the service based on measurements.

