ISO/IEC 27036-2:2022
Cybersecurity — Supplier relationships — Part 2: Requirements
Cybersecurity — Supplier relationships — Part 2: Requirements
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 38
- Дата публикации:
- 15 июня 2022 г.
- Издание:
- ISO/IEC IS 27036 edition 2 version 1
- ICS:
- 35.030
This document specifies fundamental information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining and improving supplier and acquirer relationships. These requirements cover any procurement and supply of products and services, such as manufacturing or assembly, business process procurement, software and hardware components, knowledge process procurement, build-operate-transfer and cloud computing services. This document is applicable to all organizations, regardless of type, size and nature. To meet the requirements, it is expected that an organization has internally implemented a number of foundational processes or is actively planning to do so. These processes include, but are not limited to: business management, risk management, operational and human resources management, and information security.
Abstract
Overview - ISO/IEC 27036-2:2022 (Cybersecurity - Supplier relationships - Part 2: Requirements)
ISO/IEC 27036-2:2022 specifies fundamental information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining and improving supplier–acquirer relationships. It applies to any organization (all sizes and sectors) and to any procurement or supply scenario - for example, manufacturing, business process outsourcing, software and hardware components, knowledge services, build-operate-transfer arrangements and cloud services. This second edition is aligned with ISO/IEC 15288 and is intended to set information security objectives for supplier relationships (not for certification).
Key topics and technical requirements
- Supplier relationship lifecycle: Requirements cover planning, selection, agreements, ongoing management and termination of supplier relationships.
- Agreement processes: Security-related activities required during acquisition and supply (contractual security clauses, responsibilities, access control).
- Organizational project-enabling processes: Requirements for lifecycle model management, infrastructure, project portfolio, human resources, quality and knowledge management to support secure supplier interactions.
- Technical management processes: Security expectations for project planning, assessment and control, decision and risk management, configuration and information management, measurement and quality assurance.
- Supplier-specific processes: Supplier selection, relationship agreement, supplier relationship management and termination (objectives, inputs, activities, outputs).
- Risk and assurance: Encourages mutual understanding of security approaches and risk tolerance between acquirer and supplier, and setting defined security objectives as a basis for assurance.
- Cross-references and mappings: Annexes map this standard to ISO/IEC 15288 (systems life cycle) and to ISO/IEC 27002 controls to facilitate implementation.
Practical applications - who should use it
- Procurement, vendor and supplier managers seeking a security-based framework for contracts and supplier lifecycle.
- Information security officers (CISO, ISMS teams) integrating supplier controls into an information security management system.
- Project and program managers responsible for outsourced development, manufacturing, or cloud services.
- Risk managers and auditors who need to assess supplier-related information security risks and controls.
- Suppliers and service providers wanting to align their offerings with acquirer security expectations.
Practical uses include drafting supplier security requirements into contracts, establishing supplier selection criteria, defining monitoring and review processes, and aligning internal processes (HR, change/configuration, incident handling) to supplier risk profiles.
Related standards and mappings
- ISO/IEC 27036-1 - Overview and concepts for supplier relationships
- ISO/IEC 27036-3 - ICT supply chain security guidelines
- ISO/IEC 27036-4 - Cloud services guidance
- ISO/IEC 27002 - Security controls mapping (annexed)
- ISO/IEC 15288 - Systems and software lifecycle alignment
Keywords: ISO/IEC 27036-2:2022, cybersecurity, supplier relationships, information security, supplier management, procurement security, supply chain security, cloud services, risk management.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27036-2:2022
Похожие стандарты
Стандарты, упомянутые в описании
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…
BS ISO/IEC 27036-1:2021
ДействующийCybersecurity. Supplier relationships. Overview and concepts.
ISO/IEC 27036-3:2023
ДействующийCybersecurity — Supplier relationships — Part 3: Guidelines for hardware, software, and services supply chain…
Overview ISO/IEC 27036-3:2023 - "Cybersecurity - Supplier relationships - Part 3" provides practical guidance for acquirers and suppliers of hardware, software, and services to manage information sec…