Overview
ISO/IEC 27036-3:2023 - "Cybersecurity - Supplier relationships - Part 3" provides practical guidance for acquirers and suppliers of hardware, software, and services to manage information security risks in physically dispersed, multi‑layered supply chains. The standard explains how to increase visibility, traceability and accountability across supplier networks and how to integrate supply chain security into system and software life cycle processes. It is the second edition, aligned with the latest ISO/IEC/IEEE life cycle standards.
Key Topics
- Supply chain visibility and traceability: guidance to identify where components and services originate and who “touches” them.
- Risk identification and response: approaches for assessing and responding to information security risks introduced by multi‑tier suppliers.
- Integration with life cycle processes: embedding security practices into system/software life cycles as described in ISO/IEC/IEEE 15288 and ISO/IEC/IEEE 12207.
- Mapping to ISMS controls: aligning life cycle activities with information security controls in ISO/IEC 27002.
- Essential practices: lifecycle-oriented practices (acquisition, supply, configuration management, verification, integration, maintenance, disposal).
- Software Bill of Materials (SBoM): Annex B outlines essential elements of an SBoM to support component inventories and dependency management.
- Organizational capability and relationship types: defining acquirer/supplier roles, contractual expectations, and governance for supplier relationships.
- Scope exclusions: does not address business continuity/resiliency - see ISO/IEC 27031 for ICT readiness for continuity.
Applications
ISO/IEC 27036-3:2023 is practical for:
- Embedding supply chain security into procurement, contracting and vendor management processes.
- Defining supplier security requirements and acceptance criteria for hardware, firmware and software components.
- Building or enhancing a software bill of materials (SBoM) program to improve component traceability and incident response.
- Integrating security checkpoints into the software/system development life cycle (SDLC) and maintenance workflows.
- Conducting supplier risk assessments, onboarding third parties, and managing multi‑tier outsourcing risks.
- Supporting investigations and containment when a supply chain compromise is suspected by improving traceability.
Who Should Use It
- Procurement and vendor-risk teams
- Product and platform engineering managers
- Security architects and supply chain security specialists
- Third‑party management, compliance and audit functions
- Suppliers wishing to demonstrate secure supply practices to acquirers
Related Standards
- ISO/IEC 27001 / 27002 (ISMS and controls)
- ISO/IEC 27036-1 (overview and concepts for supplier relationships)
- ISO/IEC/IEEE 15288 and ISO/IEC/IEEE 12207 (system/software life cycle processes)
- ISO/IEC 27031 (ICT readiness for business continuity)
- ISO/IEC 27000 (vocabulary and overview)
Using ISO/IEC 27036-3:2023 helps organizations strengthen software supply chain security, improve contractual clarity with suppliers, and establish life cycle‑based controls that reduce exposure to software and hardware component risks.