Overview
ISO/IEC 27036-4:2016 - Information technology - Security techniques - Information security for supplier relationships - Part 4: Guidelines for security of cloud services - provides practical guidance for cloud service customers and cloud service providers to gain visibility of information security risks from cloud services and to manage those risks effectively. It focuses on cloud‑specific security processes and controls across the cloud service acquisition lifecycle and defines how to respond to acquisition/provision risks that impact organizations using cloud services. The standard is guidance‑oriented (not an implementation manual) and specifically excludes business continuity/resiliency (see ISO/IEC 27031).
Key Topics
- Cloud risk visibility and management - Guidance to identify, assess and control information security risks introduced by cloud services and related supply chains.
- Cloud concepts and threat analysis - Characteristics of cloud computing and threats/risks mapped to public, private and hybrid deployment models.
- Lifecycle‑based security controls - Information security controls organized by the cloud service acquisition lifecycle, including:
- Agreement and acquisition/supply processes
- Organizational project‑enabling and project management processes (planning, risk management, configuration, measurement)
- Technical processes (requirements, architecture, implementation, integration, verification, transition, operation, maintenance, disposal)
- Provider controls and capability types - Guidance for setting security controls at cloud service providers across infrastructure, platform, and application capability types.
- Standards mapping and annexes - Includes informative annexes such as mappings to ISO/IEC 27017 and a catalogue of information security standards for cloud providers.
- Harmonization - Aligned with systems/software lifecycle standards (ISO/IEC 15288, ISO/IEC 12207) and intended to be used with ISO/IEC 27001/27002, ISO/IEC 27017 and ISO/IEC 27018.
Applications
Who uses ISO/IEC 27036-4 and how:
- Cloud service customers (risk owners) - to define security requirements, evaluate provider risk posture, and build assurance into procurement and acceptance decisions.
- Cloud service providers - to identify risks in services and supply chains and demonstrate measures taken to manage those risks.
- Procurement, IT security and compliance teams - to structure contracts, supplier assessments, due diligence, and ongoing monitoring of cloud supplier relationships.
- Auditors and assessors - to map cloud‑specific lifecycle controls and validate supplier controls against recognized guidance.
Practical uses include drafting supplier security requirements, conducting cloud risk assessments, selecting deployment models/security controls, and aligning cloud assurance activities with an organisation’s ISMS.
Related Standards
Keywords: ISO/IEC 27036-4, cloud security, information security, supplier relationships, cloud service risk management, cloud service customer, cloud service provider, ISO/IEC 27017.