How should we manage suppliers used by our supplier?
Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes a multi-layer ; it does not require the same questionnaire or direct audit right for every remote tier.
ISO/IEC 27036 uses supply-chain and subcontractor language rather than defining "fourth party." On this page, fourth party means a supplier, component source, service, or other dependency used behind the direct supplier. The direct supplier remains the practical route for setting upstream requirements unless another agreement gives the acquirer direct rights. A subcontractor is not automatically high risk, and a non-contractual component or open-source dependency can still be consequential.
- Identify upstream dependencies that receive privileged access or sensitive information, supply critical components, create concentration, are hard to replace, or have unclear provenance.
- Set permission or notification rules for subcontracting and require the direct supplier to pass relevant security, confidentiality, incident, evidence, audit, and disposal requirements upstream.
- Define which upstream changes or incidents require notice, what evidence the direct supplier must obtain, and who tracks corrective actions.
Part 1 defines a supply chain as successive supplier relationships and explains why an acquirer often has limited control beyond its direct supplier.
Part 2 requires subcontractor transparency criteria, including use and change notices, assurance, audit, confidentiality, and other parties exposed to acquirer information.
Part 3 addresses physically dispersed and multi-layer hardware, software, and services supply chains and recursive requirements for upstream suppliers.