FAQGlobalISO/IEC 27036

ISO/IEC 27036 FAQ Contract Controls

Which security controls belong in a supplier agreement?

Part 2 contains supplier and acquirer relationship requirements; the other parts provide concepts or guidance. Apply the relevant part proportionately and verify contractual, legal, and customer duties separately.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

Which security controls belong in a supplier agreement?

Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The should make scope, performance, evidence, communication, exceptions, change, incident coordination, and exit reviewable by both parties.

ISO/IEC 27036-2 requires the agreement process to address information-security roles, controls across information, ICT, personnel, and physical security, transition, change, incidents, compliance monitoring and enforcement, and termination. The exact clauses still depend on the product or service, risk treatment, negotiation model, and applicable law.

  • Identify the product or service, information and systems in scope, locations, approved use, service levels, responsible roles, and order of precedence between the agreement documents.
  • State each material security requirement, its owner, measure or acceptance criterion, evidence, reporting cadence, audit or assessment terms, exception process, remedy, and escalation route.
  • Address access, information handling, personnel, physical security, vulnerabilities and updates, subcontractors, incidents, changes, transition, corrective actions, and termination where the risk assessment makes them relevant.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 defines the minimum subject areas for a supplier relationship agreement and ties its controls to the relationship risk assessment and treatment plan.

ISO/IEC 27036-3:2023 standard page

Part 3 adds ICT supply-chain topics such as chain of custody, provenance, credible evidence, vulnerability response, incident sharing, upstream requirements, and disposal or retention.

Question 2

Which clauses need operational detail?

A clause should say enough for both parties to act and for a reviewer to test performance. For incident reporting, define the trigger, contact path, required initial facts, update expectations, evidence preservation, investigation support, and any deadline supplied by law or contract. ISO/IEC 27036-2 requires an agreed incident-management procedure and immediate reporting within that procedure, but it does not supply a universal number of hours. For changes, define which service, location, ownership, control, subcontractor, or technology changes require notice or approval.

For assurance and enforcement, define the reports, attestations, self-assessments, independent assessments, audit access, correction process, and consequences that apply. For termination, define transfer or cancellation, asset inventory, access removal, return, retention or destruction, communication, transition support, and completion evidence.

  • Make subcontractor permission, notification, flow-down controls, assurance, audit, confidentiality, and change duties explicit where upstream suppliers affect the risk.
  • Separate a target or recommendation from a mandatory contractual commitment.
  • State which duties survive termination, such as confidentiality, record retention, incident cooperation, intellectual-property protection, or deletion verification.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 details agreement content for roles, controls, service levels, assurance, audit, subcontractors, changes, incidents, enforcement, corrective actions, and termination.

Question 3

What if the supplier will not negotiate?

A click-through, licence, public-cloud, or other standard-form agreement can still create a supplier relationship. If the supplier will not change its terms, compare the available commitment and evidence with the requirement, record each material gap, and decide whether configuration, architecture, reduced scope, insurance, monitoring, redundancy, or another compensating control brings risk within the organization's acceptance criteria.

If the remaining risk is outside those criteria, send the decision to the authorized risk owner. Do not label the relationship compliant merely because the terms are common in the market.

  • Preserve the selected terms, incorporated documents, assessment, exceptions, approvals, and renewal or exit trigger.
  • Reassess when the supplier changes its terms, service, controls, subcontractors, location, or assurance.
  • Obtain legal advice for enforceability, liability, regulatory, or jurisdiction questions; ISO/IEC 27036 does not decide them.
Citations
Recommended next step

Put ISO/IEC 27036 FAQ: Contract Controls into practice

Capture owners, evidence, decisions, and review dates in one workflow record so supplier security controls and escalation points stay auditable over time.

Primary sources

References and citations

iso.org
Referenced sections
  • Part 1 recognizes supplier relationships based on non-negotiable end-user licence agreements, terms of use, or open-source terms.
iso.org
Referenced sections
  • Part 2 requires documented risk, selection, agreement, monitoring, and termination decisions for the relationship.
iso.org
Referenced sections
  • Part 3 supports tailored controls and evidence for ICT products and services but does not turn guidance into universal contract wording.
Related guides

Explore more topics

ISO/IEC 27036 Assurance Evidence FAQ
Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.
ISO/IEC 27036 Cloud Suppliers FAQ
Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.
ISO/IEC 27036 Contract Security Clauses Guide
Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
ISO/IEC 27036 Fourth Parties FAQ
Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-layer supply chains; it does not require the same questionnaire or direct audit right for every remote tier.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide
Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
ISO/IEC 27036 Onboarding and Offboarding Workflow
Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
ISO/IEC 27036 Risk Tiers FAQ
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036 Supplier Assurance Framework Guide
Design risk-based ISO/IEC 27036 supplier assurance with defined evidence scope, monitoring, findings, and reassessment.
ISO/IEC 27036 Supplier Incidents FAQ
Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Monitoring FAQ
ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Supplier Security FAQ
Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.
ISO/IEC 27036 Termination and Offboarding FAQ
Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.
ISO/IEC 27036 Third Party Risk Checklist
Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
ISO/IEC 27036 vs NIST SP 800-161 Comparison
Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.
Using the ISO/IEC 27036 Supplier Relationship Series
Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.