ISO/IEC 27036-4:2016
Information technology — Security techniques — Information security for supplier relationships — Part 4: Guidelines for security of cloud services
Information technology — Security techniques — Information security for supplier relationships — Part 4: Guidelines for security of cloud services
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 21
- Дата публикации:
- 28 сентября 2016 г.
- Издание:
- ISO/IEC IS 27036 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 27036-4:2016 provides cloud service customers and cloud service providers with guidance on a) gaining visibility into the information security risks associated with the use of cloud services and managing those risks effectively, and b) responding to risks specific to the acquisition or provision of cloud services that can have an information security impact on organizations using these services. ISO/IEC 27036-4:2016 does not include business continuity management/resiliency issues involved with the cloud service. ISO/IEC 27031 addresses business continuity. ISO/IEC 27036-4:2016 does not provide guidance on how a cloud service provider should implement, manage and operate information security. Guidance on those can be found in ISO/IEC 27002 and ISO/IEC 27017. The scope of ISO/IEC 27036-4:2016 is to define guidelines supporting the implementation of information security management for the use of cloud services.
Abstract
Overview
ISO/IEC 27036-4:2016 - Information technology - Security techniques - Information security for supplier relationships - Part 4: Guidelines for security of cloud services - provides practical guidance for cloud service customers and cloud service providers to gain visibility of information security risks from cloud services and to manage those risks effectively. It focuses on cloud‑specific security processes and controls across the cloud service acquisition lifecycle and defines how to respond to acquisition/provision risks that impact organizations using cloud services. The standard is guidance‑oriented (not an implementation manual) and specifically excludes business continuity/resiliency (see ISO/IEC 27031).
Key Topics
- Cloud risk visibility and management - Guidance to identify, assess and control information security risks introduced by cloud services and related supply chains.
- Cloud concepts and threat analysis - Characteristics of cloud computing and threats/risks mapped to public, private and hybrid deployment models.
- Lifecycle‑based security controls - Information security controls organized by the cloud service acquisition lifecycle, including:
- Agreement and acquisition/supply processes
- Organizational project‑enabling and project management processes (planning, risk management, configuration, measurement)
- Technical processes (requirements, architecture, implementation, integration, verification, transition, operation, maintenance, disposal)
- Provider controls and capability types - Guidance for setting security controls at cloud service providers across infrastructure, platform, and application capability types.
- Standards mapping and annexes - Includes informative annexes such as mappings to ISO/IEC 27017 and a catalogue of information security standards for cloud providers.
- Harmonization - Aligned with systems/software lifecycle standards (ISO/IEC 15288, ISO/IEC 12207) and intended to be used with ISO/IEC 27001/27002, ISO/IEC 27017 and ISO/IEC 27018.
Applications
Who uses ISO/IEC 27036-4 and how:
- Cloud service customers (risk owners) - to define security requirements, evaluate provider risk posture, and build assurance into procurement and acceptance decisions.
- Cloud service providers - to identify risks in services and supply chains and demonstrate measures taken to manage those risks.
- Procurement, IT security and compliance teams - to structure contracts, supplier assessments, due diligence, and ongoing monitoring of cloud supplier relationships.
- Auditors and assessors - to map cloud‑specific lifecycle controls and validate supplier controls against recognized guidance.
Practical uses include drafting supplier security requirements, conducting cloud risk assessments, selecting deployment models/security controls, and aligning cloud assurance activities with an organisation’s ISMS.
Related Standards
- ISO/IEC 27001 - Information security management systems (ISMS)
- ISO/IEC 27002 - Guidance on information security controls
- ISO/IEC 27017 - Cloud‑specific control implementation guidance
- ISO/IEC 27018 - Protection of personal data in the cloud
- ISO/IEC 27031 - Business continuity for ICT
- ISO/IEC 17788 / 17789 (ITU‑T Y.3500 / Y.3502) - Cloud computing vocabulary and reference architecture
Keywords: ISO/IEC 27036-4, cloud security, information security, supplier relationships, cloud service risk management, cloud service customer, cloud service provider, ISO/IEC 27017.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27036-4:2016
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 27031:2011
ОтменёнInformation technology — Security techniques — Guidelines for information and communication technology readin…
Overview - ISO/IEC 27031:2011 and ICT readiness for business continuity ISO/IEC 27031:2011 provides guidelines for information and communication technology (ICT) readiness for business continuity (IR…
ISO/IEC 12207:1995
ОтменёнInformation technology — Software life cycle processes
BS EN ISO/IEC 27018:2020
ДействующийInformation technology. Security techniques. Code of practice for protection of personally identifiable infor…
BS ISO/IEC 27036-4:2016
ДействующийInformation technology. Security techniques. Information security for supplier relationships. Guidelines for…
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…