FAQGlobalISO/IEC 27036

ISO/IEC 27036 FAQ Cloud Suppliers

How does ISO/IEC 27036 apply to cloud suppliers?

Part 2 contains supplier and acquirer relationship requirements; the other parts provide concepts or guidance. Apply the relevant part proportionately and verify contractual, legal, and customer duties separately.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Treat cloud as a supplier relationship with and perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

How does ISO/IEC 27036 apply to cloud suppliers?

Treat cloud as a supplier relationship with and perspectives. Apply ISO/IEC 27036-2:2022 relationship requirements and ISO/IEC 27036-4:2016 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services. Part 4 is guidance and does not replace cloud-specific law, regulation, sector rules, or contractual duties.

The provider's controls do not remove the customer's responsibilities. For the actual service, record who manages identities, privileged access, configuration, logging, encryption, backups, vulnerability response, incident communication, and data return or disposal. Check legal and contractual duties separately.

  • Classify the information and business process before selecting the service; record sensitivity, criticality, permitted locations, and applicable restrictions.
  • Map customer-managed and provider-managed controls for the actual service, including administrator and user access and any multi-tenant separation requirements.
  • Identify cloud services used by the provider and decide what visibility, assurance, change notice, incident support, continuity, portability, and exit evidence the relationship needs.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 supplies the fundamental requirements for planning, selecting, agreeing, monitoring, changing, and terminating a cloud supplier relationship.

ISO/IEC 27036-4:2016 standard page

Part 4 provides cloud customer and provider guidance on shared responsibilities, assurance, information location, service changes, incidents, asset transfer, and disposal.

Question 2

What should be checked before accepting the cloud service?

Review the service description, responsibility model, standard terms, service levels, data and administrative paths, provider locations, subprocessors or nested cloud services, change-notice process, available logs, assurance scope, backup and recovery capabilities, incident support, portability, and termination process.

Acceptance evidence should relate to the subscribed service and configuration. Organization-wide certification can support the decision, but it does not by itself show that the selected service, region, controls, or customer configuration meets the requirement. Public, hybrid, and private deployment labels do not settle the risk: information importance, customer control, location, privileged access, separation, logging, portability, and the actual allocation of responsibility still matter.

  • Record non-negotiable standard-term gaps and the compensating control, risk approval, or alternative service decision.
  • Test data export, restoration, administrative access, logging, and required interfaces before critical reliance where proportionate.
  • Treat portability and deletion as verifiable exit requirements, not assumptions based on a marketing description.
Citations
ISO/IEC 27036-4:2016 standard page

Part 4 identifies cloud-specific acquisition issues including responsibilities, assurance, separation, asset transfer, service changes, and disposal confirmation.

Question 3

How should cloud changes, incidents, and exit be handled?

Monitor service and provider changes against the agreed responsibility map and risk decision. Define which changes require notice, review, approval, reconfiguration, or migration. The customer and provider should also agree incident contacts and the information needed for impact assessment and response.

Before termination, export and verify required information, transfer service where needed, revoke access and integrations, and obtain the agreed evidence of disposal. Part 4 addresses cloud information return and disposal, but it does not itself provide business-continuity management guidance; use the agreement, applicable obligations, and relevant continuity standards for that work.

  • Keep change notices, impact assessments, incident records, configuration decisions, export results, and disposal confirmation with the relationship record.
  • Check backups, retained logs, legal holds, and technical deletion limits rather than promising immediate deletion in every system.
  • Close the relationship only after owners verify transition, access removal, asset handling, surviving duties, and approved exceptions.
Citations
Recommended next step

Put ISO/IEC 27036 FAQ: Cloud Suppliers into practice

Capture owners, evidence, decisions, and review dates in one workflow record so supplier security controls and escalation points stay auditable over time.

Primary sources

References and citations

iso.org
Referenced sections
  • Part 2 covers change, incident, compliance, corrective-action, and termination processes for supplier relationships.
iso.org
Referenced sections
  • Part 4 covers cloud service change monitoring, incident information, transition of customer assets, and confirmation and logging of disposal.
Related guides

Explore more topics

ISO/IEC 27036 Assurance Evidence FAQ
Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.
ISO/IEC 27036 Contract Controls FAQ
Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.
ISO/IEC 27036 Contract Security Clauses Guide
Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
ISO/IEC 27036 Fourth Parties FAQ
Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-layer supply chains; it does not require the same questionnaire or direct audit right for every remote tier.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide
Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
ISO/IEC 27036 Onboarding and Offboarding Workflow
Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
ISO/IEC 27036 Risk Tiers FAQ
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036 Supplier Assurance Framework Guide
Design risk-based ISO/IEC 27036 supplier assurance with defined evidence scope, monitoring, findings, and reassessment.
ISO/IEC 27036 Supplier Incidents FAQ
Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Monitoring FAQ
ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Supplier Security FAQ
Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.
ISO/IEC 27036 Termination and Offboarding FAQ
Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.
ISO/IEC 27036 Third Party Risk Checklist
Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
ISO/IEC 27036 vs NIST SP 800-161 Comparison
Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.
Using the ISO/IEC 27036 Supplier Relationship Series
Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.