Which security controls belong in a supplier agreement?
Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The should make scope, performance, evidence, communication, exceptions, change, incident coordination, and exit reviewable by both parties.
ISO/IEC 27036-2 requires the agreement process to address information-security roles, controls across information, ICT, personnel, and physical security, transition, change, incidents, compliance monitoring and enforcement, and termination. The exact clauses still depend on the product or service, risk treatment, negotiation model, and applicable law.
- Identify the product or service, information and systems in scope, locations, approved use, service levels, responsible roles, and order of precedence between the agreement documents.
- State each material security requirement, its owner, measure or acceptance criterion, evidence, reporting cadence, audit or assessment terms, exception process, remedy, and escalation route.
- Address access, information handling, personnel, physical security, vulnerabilities and updates, subcontractors, incidents, changes, transition, corrective actions, and termination where the risk assessment makes them relevant.
Part 2 defines the minimum subject areas for a supplier relationship agreement and ties its controls to the relationship risk assessment and treatment plan.
Part 3 adds ICT supply-chain topics such as chain of custody, provenance, credible evidence, vulnerability response, incident sharing, upstream requirements, and disposal or retention.