FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
24of24items
Across 8 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
ISO/IEC 27036 Assurance Evidence

What supplier assurance evidence should we collect?

Collect assurance evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.

ISO/IEC 27036-2:2022 sets requirements for acquirers and suppliers across the relationship lifecycle. It identifies several forms of assurance, including performance reports, attestations, self-assessments, independent assessments, audits, tested continuity plans, and ISO/IEC 27001 certification. Part 3:2023 adds hardware, software, and service supply-chain guidance. The acquirer must decide what evidence is credible and sufficient for the selected supplier and requirement.

  • Start with the requirement and decision: identify the control or risk being tested, the acceptance criteria, the reviewer, and what happens if the evidence is missing or weak.
  • Check the evidence boundary: supplier legal entity, named product or service, sites, systems, control period, exclusions, qualifications, subcontractors, and upstream components.
  • Test the result: inspect findings and corrective actions, compare claims with the agreement and other evidence, and record any residual risk or follow-up.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 requires risk-based supplier selection and agreement management and identifies several possible assurance methods rather than one mandatory evidence package.

ISO/IEC 27036-3:2023 standard page

Part 3 guides acquirers to seek credible evidence, verify supplier claims, and assess what attestations or certifications mean for the intended use.

ISO/IEC 27036 Assurance Evidence

How should each evidence type be used?

Use a certificate to confirm only the certified management-system scope and period. Use an independent audit or attestation report for the controls, system boundary, period, exceptions, and complementary responsibilities it actually covers. Use questionnaires and interviews to fill relationship-specific gaps, but verify consequential answers with records, demonstrations, tests, or other independent evidence when the risk warrants it.

Product evidence can differ from organization-level evidence. For hardware, software, and services, relevant evidence may include test results, vulnerability and remediation records, chain-of-custody records, provenance information, a software bill of materials, delivery verification, or proof that required security features work. A software bill of materials helps identify components and relationships, but it does not prove that the listed components are vulnerability-free or securely configured.

  • A policy shows intended practice; operating records show whether the practice occurred.
  • A point-in-time test does not establish performance throughout a longer review period.
  • A supplier-wide report may omit the service, region, platform, or subservice organization on which the acquirer relies.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 ties supplier assurance, audit terms, performance measures, corrective actions, and review records to the specific relationship and agreement.

ISO/IEC 27036-3:2023 standard page

Part 3 describes verification of supplier claims, attestations, certifications, product integrity, testing, provenance, and supply-chain transparency.

ISO/IEC 27036 Assurance Evidence

What decision record should be retained?

Retain the relationship and requirement being assessed, the evidence requested and received, its scope and period, the reviewer, the conclusion against stated acceptance criteria, open findings, corrective-action owner and due date, residual-risk decision, approval, and next review or event trigger.

Reassess when evidence expires or the service, product, location, ownership, subcontracting, threat exposure, agreement, or intended use changes. An incident or material control failure can require an earlier review.

  • Do not treat ISO/IEC 27036 as a standalone certification scheme or as a fixed evidence checklist.
  • Do not silently convert missing visibility into a passing result; record the limitation and its effect on risk.
  • Escalate unresolved gaps to the person authorized to require remediation, add a compensating control, accept the residual risk, or reject or exit the relationship.
Citations
ISO/IEC 27036-3:2023 standard page

Part 3 supports reassessment through verification, monitoring, vulnerability response, change records, and evidence about multi-layer supply-chain dependencies.

ISO/IEC 27036 Cloud Suppliers

How does ISO/IEC 27036 apply to cloud suppliers?

Treat cloud as a supplier relationship with cloud service customer and cloud service provider perspectives. Apply ISO/IEC 27036-2:2022 relationship requirements and ISO/IEC 27036-4:2016 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services. Part 4 is guidance and does not replace cloud-specific law, regulation, sector rules, or contractual duties.

The provider's controls do not remove the customer's responsibilities. For the actual service, record who manages identities, privileged access, configuration, logging, encryption, backups, vulnerability response, incident communication, and data return or disposal. Check legal and contractual duties separately.

  • Classify the information and business process before selecting the service; record sensitivity, criticality, permitted locations, and applicable restrictions.
  • Map customer-managed and provider-managed controls for the actual service, including administrator and user access and any multi-tenant separation requirements.
  • Identify cloud services used by the provider and decide what visibility, assurance, change notice, incident support, continuity, portability, and exit evidence the relationship needs.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 supplies the fundamental requirements for planning, selecting, agreeing, monitoring, changing, and terminating a cloud supplier relationship.

ISO/IEC 27036-4:2016 standard page

Part 4 provides cloud customer and provider guidance on shared responsibilities, assurance, information location, service changes, incidents, asset transfer, and disposal.

ISO/IEC 27036 Cloud Suppliers

What should be checked before accepting the cloud service?

Review the service description, responsibility model, standard terms, service levels, data and administrative paths, provider locations, subprocessors or nested cloud services, change-notice process, available logs, assurance scope, backup and recovery capabilities, incident support, portability, and termination process.

Acceptance evidence should relate to the subscribed service and configuration. Organization-wide certification can support the decision, but it does not by itself show that the selected service, region, controls, or customer configuration meets the requirement. Public, hybrid, and private deployment labels do not settle the risk: information importance, customer control, location, privileged access, separation, logging, portability, and the actual allocation of responsibility still matter.

  • Record non-negotiable standard-term gaps and the compensating control, risk approval, or alternative service decision.
  • Test data export, restoration, administrative access, logging, and required interfaces before critical reliance where proportionate.
  • Treat portability and deletion as verifiable exit requirements, not assumptions based on a marketing description.
Citations
ISO/IEC 27036-4:2016 standard page

Part 4 identifies cloud-specific acquisition issues including responsibilities, assurance, separation, asset transfer, service changes, and disposal confirmation.

ISO/IEC 27036 Cloud Suppliers

How should cloud changes, incidents, and exit be handled?

Monitor service and provider changes against the agreed responsibility map and risk decision. Define which changes require notice, review, approval, reconfiguration, or migration. The customer and provider should also agree incident contacts and the information needed for impact assessment and response.

Before termination, export and verify required information, transfer service where needed, revoke access and integrations, and obtain the agreed evidence of disposal. Part 4 addresses cloud information return and disposal, but it does not itself provide business-continuity management guidance; use the agreement, applicable obligations, and relevant continuity standards for that work.

  • Keep change notices, impact assessments, incident records, configuration decisions, export results, and disposal confirmation with the relationship record.
  • Check backups, retained logs, legal holds, and technical deletion limits rather than promising immediate deletion in every system.
  • Close the relationship only after owners verify transition, access removal, asset handling, surviving duties, and approved exceptions.
Citations
ISO/IEC 27036 Contract Controls

Which security controls belong in a supplier agreement?

Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The supplier relationship agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, and exit reviewable by both parties.

ISO/IEC 27036-2 requires the agreement process to address information-security roles, controls across information, ICT, personnel, and physical security, transition, change, incidents, compliance monitoring and enforcement, and termination. The exact clauses still depend on the product or service, risk treatment, negotiation model, and applicable law.

  • Identify the product or service, information and systems in scope, locations, approved use, service levels, responsible roles, and order of precedence between the agreement documents.
  • State each material security requirement, its owner, measure or acceptance criterion, evidence, reporting cadence, audit or assessment terms, exception process, remedy, and escalation route.
  • Address access, information handling, personnel, physical security, vulnerabilities and updates, subcontractors, incidents, changes, transition, corrective actions, and termination where the risk assessment makes them relevant.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 defines the minimum subject areas for a supplier relationship agreement and ties its controls to the relationship risk assessment and treatment plan.

ISO/IEC 27036-3:2023 standard page

Part 3 adds ICT supply-chain topics such as chain of custody, provenance, credible evidence, vulnerability response, incident sharing, upstream requirements, and disposal or retention.

ISO/IEC 27036 Contract Controls

Which clauses need operational detail?

A clause should say enough for both parties to act and for a reviewer to test performance. For incident reporting, define the trigger, contact path, required initial facts, update expectations, evidence preservation, investigation support, and any deadline supplied by law or contract. ISO/IEC 27036-2 requires an agreed incident-management procedure and immediate reporting within that procedure, but it does not supply a universal number of hours. For changes, define which service, location, ownership, control, subcontractor, or technology changes require notice or approval.

For assurance and enforcement, define the reports, attestations, self-assessments, independent assessments, audit access, correction process, and consequences that apply. For termination, define transfer or cancellation, asset inventory, access removal, return, retention or destruction, communication, transition support, and completion evidence.

  • Make subcontractor permission, notification, flow-down controls, assurance, audit, confidentiality, and change duties explicit where upstream suppliers affect the risk.
  • Separate a target or recommendation from a mandatory contractual commitment.
  • State which duties survive termination, such as confidentiality, record retention, incident cooperation, intellectual-property protection, or deletion verification.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 details agreement content for roles, controls, service levels, assurance, audit, subcontractors, changes, incidents, enforcement, corrective actions, and termination.

ISO/IEC 27036 Contract Controls

What if the supplier will not negotiate?

A click-through, licence, public-cloud, or other standard-form agreement can still create a supplier relationship. If the supplier will not change its terms, compare the available commitment and evidence with the requirement, record each material gap, and decide whether configuration, architecture, reduced scope, insurance, monitoring, redundancy, or another compensating control brings risk within the organization's acceptance criteria.

If the remaining risk is outside those criteria, send the decision to the authorized risk owner. Do not label the relationship compliant merely because the terms are common in the market.

  • Preserve the selected terms, incorporated documents, assessment, exceptions, approvals, and renewal or exit trigger.
  • Reassess when the supplier changes its terms, service, controls, subcontractors, location, or assurance.
  • Obtain legal advice for enforceability, liability, regulatory, or jurisdiction questions; ISO/IEC 27036 does not decide them.
Citations
ISO/IEC 27036 Fourth Parties

How should we manage suppliers used by our supplier?

Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes a multi-layer supply chain; it does not require the same questionnaire or direct audit right for every remote tier.

ISO/IEC 27036 uses supply-chain and subcontractor language rather than defining "fourth party." On this page, fourth party means a supplier, component source, service, or other dependency used behind the direct supplier. The direct supplier remains the practical route for setting upstream requirements unless another agreement gives the acquirer direct rights. A subcontractor is not automatically high risk, and a non-contractual component or open-source dependency can still be consequential.

  • Identify upstream dependencies that receive privileged access or sensitive information, supply critical components, create concentration, are hard to replace, or have unclear provenance.
  • Set permission or notification rules for subcontracting and require the direct supplier to pass relevant security, confidentiality, incident, evidence, audit, and disposal requirements upstream.
  • Define which upstream changes or incidents require notice, what evidence the direct supplier must obtain, and who tracks corrective actions.
Citations
ISO/IEC 27036-1:2021 standard page

Part 1 defines a supply chain as successive supplier relationships and explains why an acquirer often has limited control beyond its direct supplier.

ISO/IEC 27036-2:2022 standard page

Part 2 requires subcontractor transparency criteria, including use and change notices, assurance, audit, confidentiality, and other parties exposed to acquirer information.

ISO/IEC 27036-3:2023 standard page

Part 3 addresses physically dispersed and multi-layer hardware, software, and services supply chains and recursive requirements for upstream suppliers.

ISO/IEC 27036 Fourth Parties

How far into the supply chain should review go?

Go as far as the relationship risk and available influence justify. Start with the function and exposure, not a fixed number of tiers. A remote supplier can deserve attention when it controls a critical component, processes sensitive information, has privileged access, is a single source, or creates a shared dependency across several direct suppliers.

For lower-impact dependencies, evidence that the direct supplier operates an effective upstream risk process may be enough. For a critical dependency, ask for the identity or category, function, location, change and incident duties, assurance evidence, alternatives, and recovery or substitution plan. If identity cannot be disclosed, record the visibility limit and assess whether other evidence or controls are sufficient.

  • Map the dependency to the product or service and to the information, access, component, or business function it affects.
  • Record the direct supplier's responsibility for selection, monitoring, incident escalation, remediation, and replacement.
  • Reassess after a material upstream change, incident, vulnerability, acquisition, location change, loss of support, or concentration increase.
Citations
ISO/IEC 27036-1:2021 standard page

Part 1 explains that supply-chain risk and visibility depend on the acquirer's position and that control generally decreases beyond the direct supplier.

ISO/IEC 27036-2:2022 standard page

Part 2 supports risk-proportionate selection criteria, subcontractor transparency, assurance, change management, incident handling, and corrective action.

ISO/IEC 27036-3:2023 standard page

Part 3 guides visibility, traceability, credible evidence, upstream requirements, vulnerability response, monitoring, and component or service substitution.

ISO/IEC 27036 Fourth Parties

What if visibility is limited?

Limited visibility leaves the dependency's security unproven. Record what is unknown, why it matters, which direct-supplier evidence was reviewed, and which controls reduce the exposure. Options can include segmentation, least privilege, data minimization, verified updates, inventory and provenance records, diverse supply, substitution, monitoring, or explicit residual-risk acceptance.

Do not promise direct audit rights over an upstream supplier unless an agreement grants them. ISO/IEC 27036 supports proportionate visibility and recursive requirements; it does not create contractual privity or a universal right to inspect every tier.

  • Escalate an unresolved critical dependency to the person authorized to require remediation, change the architecture, approve the residual risk, or choose another supplier.
  • Keep the dependency map, evidence, limitations, decision, owner, and next review trigger with the direct relationship record.
  • Verify any legal, regulatory, or customer flow-down duty separately from ISO/IEC 27036.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 provides requirements for risk treatment, subcontractor criteria, assurance, monitoring, change, incident, and corrective-action records.

ISO/IEC 27036 Risk Tiers

Does ISO/IEC 27036 prescribe supplier risk tiers?

No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.

ISO/IEC 27036-2:2022 requires the acquirer's risk assessment to be commensurate with the criticality of the product or service and requires an acceptable risk level and treatment plan. A tier is an internal way to apply those decisions consistently; it is not an ISO classification or certificate and does not replace the relationship-specific assessment.

  • Assess impact: information sensitivity, business and safety effect, legal or customer duties, recovery needs, and consequences of loss, compromise, or failure.
  • Assess exposure and dependency: privileged or remote access, hosting or processing, integration, location, subcontractors, concentration, substitutability, provenance, and change rate.
  • Use the result to set selection approval, required agreement terms, evidence depth, monitoring, incident escalation, continuity and exit planning, and the authority needed to accept exceptions.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 requires a criticality-commensurate risk assessment, acceptable risk level, risk treatment, management decision, and relationship-specific requirements.

ISO/IEC 27036 Risk Tiers

How can a tier model be designed?

Define each factor, data source, scoring or decision rule, override, approver, and resulting treatment before applying labels. Keep impact separate from control evidence: a critical supplier does not become low impact because it has strong assurance, and weak evidence does not by itself describe the business consequence of failure. Calculate or decide inherent risk first, evaluate controls and evidence, then record residual risk and the resulting tier or treatment.

Allow an override when one fact dominates the result, such as unrestricted production access, regulated data, a single-source critical component, or an exit time longer than the business can tolerate. Record the reason instead of changing inputs to force the expected tier.

  • State what each tier changes, such as approval level, evidence, contract clauses, review schedule, testing, incident escalation, or exit exercise.
  • Set a minimum scheduled review where useful, then add event-driven triggers; ISO/IEC 27036 does not supply a universal interval.
  • Apply the model to the scoped product or service relationship, not only to the supplier's corporate name.
Citations
ISO/IEC 27036 Risk Tiers

When should a tier be changed?

Reassess when the product or service scope, information, access, integration, location, supplier ownership or financial condition, subcontractors, concentration, support status, threat exposure, agreement, law, or business criticality changes. Incidents, repeated findings, missed corrective actions, and failed recovery or exit tests are also useful triggers.

Keep the prior tier, evidence, rationale, approver, effective date, treatment changes, and next review. If the tier remains unchanged after a material event, record why the existing treatment is still sufficient.

  • Do not use spend as the only proxy for security impact; a low-cost service or component can still be critical.
  • Do not let a corporate certificate automatically lower the tier without checking its scope and the relationship's remaining risk.
  • Do not average away a decisive risk or hide an exception inside a general supplier score.
Citations
Page 1 of 2
Previous12Next