- ISMS requirements and audit context where supplier security evidence is commonly required.
References and citations
- Baseline controls where ISO 27036 provides more detailed supplier relationship guidance.
- Overview and key concepts, including supply chain and cloud computing risk considerations.
- Requirements framework and supplier relationship life cycle processes used as agreement requirements and for monitoring.
- Guidelines for hardware, software, and services supply chain security across life cycle processes.
- Cloud services supplier relationship guidance across the lifecycle.