Overview - ISO/IEC 27036-2:2022 (Cybersecurity - Supplier relationships - Part 2: Requirements)
ISO/IEC 27036-2:2022 specifies fundamental information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining and improving supplier–acquirer relationships. It applies to any organization (all sizes and sectors) and to any procurement or supply scenario - for example, manufacturing, business process outsourcing, software and hardware components, knowledge services, build-operate-transfer arrangements and cloud services. This second edition is aligned with ISO/IEC 15288 and is intended to set information security objectives for supplier relationships (not for certification).
Key topics and technical requirements
- Supplier relationship lifecycle: Requirements cover planning, selection, agreements, ongoing management and termination of supplier relationships.
- Agreement processes: Security-related activities required during acquisition and supply (contractual security clauses, responsibilities, access control).
- Organizational project-enabling processes: Requirements for lifecycle model management, infrastructure, project portfolio, human resources, quality and knowledge management to support secure supplier interactions.
- Technical management processes: Security expectations for project planning, assessment and control, decision and risk management, configuration and information management, measurement and quality assurance.
- Supplier-specific processes: Supplier selection, relationship agreement, supplier relationship management and termination (objectives, inputs, activities, outputs).
- Risk and assurance: Encourages mutual understanding of security approaches and risk tolerance between acquirer and supplier, and setting defined security objectives as a basis for assurance.
- Cross-references and mappings: Annexes map this standard to ISO/IEC 15288 (systems life cycle) and to ISO/IEC 27002 controls to facilitate implementation.
Practical applications - who should use it
- Procurement, vendor and supplier managers seeking a security-based framework for contracts and supplier lifecycle.
- Information security officers (CISO, ISMS teams) integrating supplier controls into an information security management system.
- Project and program managers responsible for outsourced development, manufacturing, or cloud services.
- Risk managers and auditors who need to assess supplier-related information security risks and controls.
- Suppliers and service providers wanting to align their offerings with acquirer security expectations.
Practical uses include drafting supplier security requirements into contracts, establishing supplier selection criteria, defining monitoring and review processes, and aligning internal processes (HR, change/configuration, incident handling) to supplier risk profiles.
Related standards and mappings
Keywords: ISO/IEC 27036-2:2022, cybersecurity, supplier relationships, information security, supplier management, procurement security, supply chain security, cloud services, risk management.