Overview
ISO/IEC 27036-1:2021 - Cybersecurity: Supplier relationships (Part 1: Overview and concepts) is the introductory part of the ISO/IEC 27036 series. It presents core concepts, terminology and the high-level scope for managing information security within supplier–acquirer relationships. The standard addresses both acquirers and suppliers, explains motives for using suppliers (outsourcing, specialized skills, cloud services, etc.), and frames how supplier relationships can create information security risks that must be assessed and treated.
Key topics and technical concepts
This part focuses on conceptual guidance rather than prescriptive controls. Major topics include:
- Terms and definitions relevant to supplier relationships (acquirer, supplier, supply chain, lifecycle, trust, visibility).
- Motivations for supplier relationships (cost, specialization, geographic enablement, utilities, ICT resources).
- Types of supplier relationships:
- Supplier relationships for products
- Supplier relationships for services
- ICT supply chain and upstream/downstream interactions
- Cloud computing models (SaaS/PaaS/IaaS) and their implications
- Information security risks and associated threats arising from supplier access, product vulnerabilities, production processes and contractual arrangements.
- Risk management approaches for supplier relationships, including governance, business management, operational and human resources processes that support security objectives.
- Visibility, trust and lifecycle considerations for suppliers and supply chains.
Note: detailed requirements and controls are provided in other parts of the ISO/IEC 27036 series (see Related Standards).
Practical applications - who should use it
ISO/IEC 27036-1 is intended for organizations that procure or supply products and services with information security implications. Typical users:
- CISOs, security and risk managers integrating supplier security into an ISMS (e.g., ISO/IEC 27001/27002)
- Procurement, vendor management and legal teams drafting contracts and SLAs that address security obligations
- Cloud service providers and ICT suppliers seeking to align offerings with supplier-security expectations
- Auditors and compliance teams mapping supplier risk, visibility and lifecycle controls
- SMEs and enterprise teams implementing supplier risk assessments, due diligence, and supply chain visibility
Practical uses include supplier risk assessment frameworks, contract and SLA clauses, vendor onboarding/offboarding processes, audit and monitoring plans, and integrating supplier security within incident response and business continuity planning.
Related standards
By clarifying concepts and framing risks across supplier ecosystems, ISO/IEC 27036-1 helps organizations build consistent, standards-aligned approaches to supplier cybersecurity, ICT supply chain protection, and secure cloud sourcing.