How does ISO/IEC 27036 apply to cloud suppliers?
Treat cloud as a supplier relationship with and perspectives. Apply ISO/IEC 27036-2:2022 relationship requirements and ISO/IEC 27036-4:2016 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services. Part 4 is guidance and does not replace cloud-specific law, regulation, sector rules, or contractual duties.
The provider's controls do not remove the customer's responsibilities. For the actual service, record who manages identities, privileged access, configuration, logging, encryption, backups, vulnerability response, incident communication, and data return or disposal. Check legal and contractual duties separately.
- Classify the information and business process before selecting the service; record sensitivity, criticality, permitted locations, and applicable restrictions.
- Map customer-managed and provider-managed controls for the actual service, including administrator and user access and any multi-tenant separation requirements.
- Identify cloud services used by the provider and decide what visibility, assurance, change notice, incident support, continuity, portability, and exit evidence the relationship needs.
Part 2 supplies the fundamental requirements for planning, selecting, agreeing, monitoring, changing, and terminating a cloud supplier relationship.
Part 4 provides cloud customer and provider guidance on shared responsibilities, assurance, information location, service changes, incidents, asset transfer, and disposal.