Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
While ISO/IEC 27036-1 provides concepts and an overview framework, ISO/IEC 27036-2:2014 defines the specific requirements for establishing, implementing, and maintaining information security in supplier relationships. This requirements standard is designed for use by both acquirers (organizations procuring products or services) and suppliers (organizations providing products or services), providing a common set of expectations that can be incorporated into contracts and service agreements.
The standard requires that organizations define information security requirements for supplier relationships based on a systematic risk assessment. These requirements must address: the type of relationship (product supply, service provision, outsourcing), the sensitivity and criticality of the information and systems involved, the applicable legal and regulatory obligations, and the business impact of potential security failures. Requirements must be documented, reviewed, and agreed upon by both parties before the relationship commences.
Key requirements categories defined in the standard include: access control (who can access what, under what conditions), personnel security (screening, training, confidentiality agreements), physical and environmental security (facilities protection for supplier operations), incident management (detection, reporting, and response obligations), business continuity and disaster recovery (resilience requirements and testing), compliance and audit (right to audit, reporting obligations), and information handling (classification, storage, transmission, and disposal).
| Requirement Domain | Specific Requirements | Verification Method |
|---|---|---|
| Access Control | Need-to-base access, authentication, authorization, review | Access reviews, audit logs |
| Personnel Security | Background checks, security training, NDAs | Training records, signed agreements |
| Incident Management | Detection capability, reporting timelines, cooperation | Incident reports, post-incident reviews |
| Business Continuity | BCP/DRP documentation, testing, recovery objectives | Test results, BCP reviews |
| Compliance & Audit | Right to audit, evidence of compliance, remediation | Audit reports, remediation plans |
| Information Handling | Classification, secure storage, transmission, disposal | Data flow mapping, disposal certificates |
ISO/IEC 27036-2 maps requirements to the acquisition lifecycle phases. During planning and risk assessment, the acquirer must identify and evaluate information security risks associated with the proposed supplier relationship. During supplier selection and evaluation, security capability must be a formal evaluation criterion. During contracting, security requirements must be incorporated into legally binding agreements with provisions for monitoring, audit, and remedies for non-compliance.
During operations and monitoring, the acquirer must establish processes for ongoing oversight of supplier security performance, including regular security assessments, monitoring of security events, and management of changes (to the supplier’s environment, personnel, sub-suppliers, or processes). During change and transition, requirements address both planned changes (upgrades, migrations) and unplanned changes (incidents, supplier financial distress). During termination, requirements cover secure return or destruction of information, transition of services, and post-termination obligations.
The standard goes beyond initial requirements definition to address ongoing monitoring and continuous improvement. Acquirers must establish processes to: monitor supplier compliance with security requirements (through reports, assessments, and audits), track and respond to security incidents involving the supplier, review and update requirements as risks and threats evolve, and conduct periodic reviews of the supplier relationship’s continuing business case and risk profile.
Importantly, the standard requires that monitoring activities be proportionate to risk. High-risk relationships warrant more frequent and more intrusive monitoring (including on-site audits, penetration testing, and continuous security monitoring), while low-risk relationships may be managed through periodic self-assessments and contractual reporting. The standard also recommends that organizations maintain a supplier security scorecard program to provide an aggregated view of supplier risk posture and track improvement over time.
No download files available yet