How should teams handle Cloud Suppliers under ISO/IEC 27036?
Start with the operational decision: define what Cloud Suppliers means in your ISO/IEC 27036 scope, who owns it, and what record proves the decision is current.
For cloud security work, write the provider/customer split before requesting evidence; the same control can be provider-owned, customer-owned, or shared depending on the service model and contract. This keeps the answer useful in audits, customer reviews, incidents, supplier reviews, and management review.
- Name the accountable owner and reviewer for Cloud Suppliers.
- Record the scope, assumptions, decision, approval date, evidence location, exception status, and next review trigger.
- Escalate when Cloud Suppliers changes risk acceptance, service commitments, customer promises, regulatory duties, or certification evidence.
Primary ISO listing for supplier relationship security overview and concepts.
Primary ISO listing for supplier and acquirer relationship requirements.