ISO/IEC 27036-3:2023 PDF
Cybersecurity — Supplier relationships — Part 3: Guidelines for hardware, software, and services supply chain security
Cybersecurity — Supplier relationships — Part 3: Guidelines for hardware, software, and services supply chain security
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 35
- Дата публикации:
- 13 июня 2023 г.
- Издание:
- ISO/IEC IS 27036 edition 2 version 1
- ICS:
- 35.030
This document provides guidance for product and service acquirers, as well as suppliers of hardware, software and services, regarding: a) gaining visibility into and managing the information security risks caused by physically dispersed and multi-layered hardware, software, and services supply chains; b) responding to risks stemming from this physically dispersed and multi-layered hardware, software, and services supply chain that can have an information security impact on the organizations using these products and services; c) integrating information security processes and practices into the system and software life cycle processes, as described in ISO/IEC/IEEE 15288 and ISO/IEC/IEEE 12207, while supporting information security controls, as described in ISO/IEC 27002. This document does not include business continuity management/resiliency issues involved with the hardware, software, and services supply chain. ISO/IEC 27031 addresses information and communication technology readiness for business continuity.
Abstract
Overview
ISO/IEC 27036-3:2023 - "Cybersecurity - Supplier relationships - Part 3" provides practical guidance for acquirers and suppliers of hardware, software, and services to manage information security risks in physically dispersed, multi‑layered supply chains. The standard explains how to increase visibility, traceability and accountability across supplier networks and how to integrate supply chain security into system and software life cycle processes. It is the second edition, aligned with the latest ISO/IEC/IEEE life cycle standards.
Key Topics
- Supply chain visibility and traceability: guidance to identify where components and services originate and who “touches” them.
- Risk identification and response: approaches for assessing and responding to information security risks introduced by multi‑tier suppliers.
- Integration with life cycle processes: embedding security practices into system/software life cycles as described in ISO/IEC/IEEE 15288 and ISO/IEC/IEEE 12207.
- Mapping to ISMS controls: aligning life cycle activities with information security controls in ISO/IEC 27002.
- Essential practices: lifecycle-oriented practices (acquisition, supply, configuration management, verification, integration, maintenance, disposal).
- Software Bill of Materials (SBoM): Annex B outlines essential elements of an SBoM to support component inventories and dependency management.
- Organizational capability and relationship types: defining acquirer/supplier roles, contractual expectations, and governance for supplier relationships.
- Scope exclusions: does not address business continuity/resiliency - see ISO/IEC 27031 for ICT readiness for continuity.
Applications
ISO/IEC 27036-3:2023 is practical for:
- Embedding supply chain security into procurement, contracting and vendor management processes.
- Defining supplier security requirements and acceptance criteria for hardware, firmware and software components.
- Building or enhancing a software bill of materials (SBoM) program to improve component traceability and incident response.
- Integrating security checkpoints into the software/system development life cycle (SDLC) and maintenance workflows.
- Conducting supplier risk assessments, onboarding third parties, and managing multi‑tier outsourcing risks.
- Supporting investigations and containment when a supply chain compromise is suspected by improving traceability.
Who Should Use It
- Procurement and vendor-risk teams
- Product and platform engineering managers
- Security architects and supply chain security specialists
- Third‑party management, compliance and audit functions
- Suppliers wishing to demonstrate secure supply practices to acquirers
Related Standards
- ISO/IEC 27001 / 27002 (ISMS and controls)
- ISO/IEC 27036-1 (overview and concepts for supplier relationships)
- ISO/IEC/IEEE 15288 and ISO/IEC/IEEE 12207 (system/software life cycle processes)
- ISO/IEC 27031 (ICT readiness for business continuity)
- ISO/IEC 27000 (vocabulary and overview)
Using ISO/IEC 27036-3:2023 helps organizations strengthen software supply chain security, improve contractual clarity with suppliers, and establish life cycle‑based controls that reduce exposure to software and hardware component risks.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27036-3:2023
Похожие стандарты
Стандарты, упомянутые в описании
BS EN ISO/IEC 27017:2021
ОтменёнInformation technology. Security techniques. Code of practice for information security controls based on ISO/…
1 Scope This Recommendation International Standard gives guidelines for information security controls applicable to the provision and use of cloud services by providing: – additional implementation g…
BS ISO/IEC 27031:2011
ОтменёнInformation technology. Security techniques. Guidelines for information and communication technology readines…
What is BS ISO/IEC 27031:2011? BS ISO/IEC 27031 gives best-practice guidelines for information and communication technology (ICT) to ensure business continuity. Since most processes in an organizatio…
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…
BS ISO/IEC 27036-1:2014
ОтменёнInformation technology. Security techniques. Information security for supplier relationships - Overview and c…
1 Scope This part of ISO/IEC 27036 is an introductory part of ISO/IEC 27036. It provides an overview of the guidance intended to assist organizations in securing their information and information sys…
BS EN ISO/IEC 27000:2020
ОтменёнInformation technology. Security techniques. Information security management systems. Overview and vocabulary
1 Scope This document provides the overview of information security management systems (ISMS). It also provides terms and definitions commonly used in the ISMS family of standards. This document is a…