How should supplier incidents be handled under ISO/IEC 27036?
Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an information security incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
ISO/IEC 27036-2:2022 requires the supplier agreement to contain an incident-management procedure and requires both parties to follow the agreed procedure. The standard calls for immediate reporting within that procedure, but the parties and applicable authorities still determine the reportable trigger, recipient, clock, and required content. Part 3:2023 adds supply-chain concerns, including sharing incident information upstream and downstream, responding to vulnerabilities, and examining whether the underlying weakness also affects other components or services.
- Define reportable events, severity or impact triggers, primary and backup contacts, secure channels, initial information, update cadence, closure criteria, and escalation when facts are incomplete.
- Require enough information to identify affected products, services, versions, systems, data, locations, accounts, time periods, upstream dependencies, indicators, containment, and customer actions.
- Assign responsibility for investigation support, evidence preservation, vulnerability remediation, recovery, communications, legal or regulatory assessment, and corrective-action tracking.
Part 2 requires incident-management terms in the agreement and coordinated incident handling, records, corrective actions, and agreement updates.
Part 3 guides incident and vulnerability information sharing across the supply chain and supplier support for investigation and remediation.
Part 4 guides cloud customers to collect and respond to cloud incidents and cloud providers to supply agreed information and functionality.