- ISMS context where supplier assurance evidence is commonly required.
References and citations
- Baseline controls; ISO 27036 provides more detailed supplier relationship guidance.
- Overview and concepts: supplier relationship types, risks, interdependencies, and indirect suppliers.
- Normative requirements; defines supplier relationship life cycle processes and monitoring/enforcement expectations.
- Guidelines for hardware, software, and services supply chain security and deeper life cycle coverage.
- Cloud services supplier relationship guidance across lifecycle and supply chain links.