ISO/IEC 27036-1:2021
Cybersecurity — Supplier relationships — Part 1: Overview and concepts
Cybersecurity — Supplier relationships — Part 1: Overview and concepts
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 12
- Дата публикации:
- 9 сентября 2021 г.
- Издание:
- ISO/IEC IS 27036 edition 2 version 1
- ICS:
- 35.030
This document is an introductory part of ISO/IEC 27036. It provides an overview of the guidance intended to assist organizations in securing their information and information systems within the context of supplier relationships. It also introduces concepts that are described in detail in the other parts of ISO/IEC 27036. This document addresses perspectives of both acquirers and suppliers.
Abstract
Overview
ISO/IEC 27036-1:2021 - Cybersecurity: Supplier relationships (Part 1: Overview and concepts) is the introductory part of the ISO/IEC 27036 series. It presents core concepts, terminology and the high-level scope for managing information security within supplier–acquirer relationships. The standard addresses both acquirers and suppliers, explains motives for using suppliers (outsourcing, specialized skills, cloud services, etc.), and frames how supplier relationships can create information security risks that must be assessed and treated.
Key topics and technical concepts
This part focuses on conceptual guidance rather than prescriptive controls. Major topics include:
- Terms and definitions relevant to supplier relationships (acquirer, supplier, supply chain, lifecycle, trust, visibility).
- Motivations for supplier relationships (cost, specialization, geographic enablement, utilities, ICT resources).
- Types of supplier relationships:
- Supplier relationships for products
- Supplier relationships for services
- ICT supply chain and upstream/downstream interactions
- Cloud computing models (SaaS/PaaS/IaaS) and their implications
- Information security risks and associated threats arising from supplier access, product vulnerabilities, production processes and contractual arrangements.
- Risk management approaches for supplier relationships, including governance, business management, operational and human resources processes that support security objectives.
- Visibility, trust and lifecycle considerations for suppliers and supply chains.
Note: detailed requirements and controls are provided in other parts of the ISO/IEC 27036 series (see Related Standards).
Practical applications - who should use it
ISO/IEC 27036-1 is intended for organizations that procure or supply products and services with information security implications. Typical users:
- CISOs, security and risk managers integrating supplier security into an ISMS (e.g., ISO/IEC 27001/27002)
- Procurement, vendor management and legal teams drafting contracts and SLAs that address security obligations
- Cloud service providers and ICT suppliers seeking to align offerings with supplier-security expectations
- Auditors and compliance teams mapping supplier risk, visibility and lifecycle controls
- SMEs and enterprise teams implementing supplier risk assessments, due diligence, and supply chain visibility
Practical uses include supplier risk assessment frameworks, contract and SLA clauses, vendor onboarding/offboarding processes, audit and monitoring plans, and integrating supplier security within incident response and business continuity planning.
Related standards
- ISO/IEC 27036 series:
- ISO/IEC 27036-2 - Requirements (detailed requirements for supplier relationships)
- ISO/IEC 27036-3 - Guidelines for ICT supply chain security
- ISO/IEC 27036-4 - Guidelines for security of cloud services
- ISO/IEC 27001 / ISO/IEC 27002 - Information security management system standards that ISO/IEC 27036 complements
- ISO/IEC 27000 - Overview and vocabulary referenced for terms
By clarifying concepts and framing risks across supplier ecosystems, ISO/IEC 27036-1 helps organizations build consistent, standards-aligned approaches to supplier cybersecurity, ICT supply chain protection, and secure cloud sourcing.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27036-1:2021
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO/IEC 27036-2:2022
ДействующийCybersecurity. Supplier relationships. Requirements.
BS ISO/IEC 27036-1:2021
ДействующийCybersecurity. Supplier relationships. Overview and concepts.
ISO/IEC 27036-3:2023
ДействующийCybersecurity — Supplier relationships — Part 3: Guidelines for hardware, software, and services supply chain…
Overview ISO/IEC 27036-3:2023 - "Cybersecurity - Supplier relationships - Part 3" provides practical guidance for acquirers and suppliers of hardware, software, and services to manage information sec…
BS ISO/IEC 27036-4:2016
ДействующийInformation technology. Security techniques. Information security for supplier relationships. Guidelines for…
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…