FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
24of24items
Across 8 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
ISO/IEC 27036 Supplier Incidents

How should supplier incidents be handled under ISO/IEC 27036?

Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an information security incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.

ISO/IEC 27036-2:2022 requires the supplier agreement to contain an incident-management procedure and requires both parties to follow the agreed procedure. The standard calls for immediate reporting within that procedure, but the parties and applicable authorities still determine the reportable trigger, recipient, clock, and required content. Part 3:2023 adds supply-chain concerns, including sharing incident information upstream and downstream, responding to vulnerabilities, and examining whether the underlying weakness also affects other components or services.

  • Define reportable events, severity or impact triggers, primary and backup contacts, secure channels, initial information, update cadence, closure criteria, and escalation when facts are incomplete.
  • Require enough information to identify affected products, services, versions, systems, data, locations, accounts, time periods, upstream dependencies, indicators, containment, and customer actions.
  • Assign responsibility for investigation support, evidence preservation, vulnerability remediation, recovery, communications, legal or regulatory assessment, and corrective-action tracking.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 requires incident-management terms in the agreement and coordinated incident handling, records, corrective actions, and agreement updates.

ISO/IEC 27036 Supplier Incidents

What should the first supplier notification contain?

The first notice should identify what happened or is suspected, when it was detected, the affected service or product, known time window and scope, current operational and information-security impact, containment already taken, whether an upstream supplier is involved, actions the acquirer should take, and the next update time. Mark unknown facts as unknown rather than delaying all notice for a complete investigation.

The contract or incident procedure should say how the supplier protects sensitive investigation material while still giving the acquirer enough information to assess impact and meet its own duties. Where law imposes a deadline or content requirement, record that source separately and make the contractual process capable of supporting it.

  • Log every notice, update, decision, evidence item, request, response, and responsible owner against a common incident identifier.
  • Preserve relevant logs, images, samples, timelines, communications, and chain of custody according to the agreed procedure and applicable duties.
  • Do not require the supplier to state an unsupported root cause in the first notice; require corrections when material facts change.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 requires agreed incident procedures, exchange of needed information, incident history, corrective actions, and updated agreement terms where needed.

ISO/IEC 27036-3:2023 standard page

Part 3 supports traceability, incident information sharing, secure exchange of logs and error information, vulnerability response, and supply-chain impact analysis.

ISO/IEC 27036 Supplier Incidents

What happens after containment?

Track eradication, recovery, affected-version or service status, corrective actions, owners, due dates, and evidence of completion. Reassess the relationship risk, supplier controls, upstream dependencies, monitoring, assurance, agreement terms, and any downstream commitment the acquirer has made to customers or authorities.

Close the incident only when the agreed closure criteria are met or an authorized owner accepts the remaining actions and risk. Preserve a record of the incident and related decisions for the period required by the agreement, policy, and applicable law.

  • Test whether the same vulnerability, component, credential, process, or upstream supplier affects other products or relationships.
  • Update playbooks, contacts, monitoring, acceptance criteria, and agreement language when the incident exposes a gap.
  • Do not describe ISO/IEC 27036 as setting a universal reporting clock, regulator notice, or liability rule.
Citations
ISO/IEC 27036-3:2023 standard page

Part 3 guides vulnerability remediation, incident response support, traceability, verification, and review across hardware, software, and service dependencies.

ISO/IEC 27036 Supplier Monitoring

How often should suppliers be monitored?

ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.

ISO/IEC 27036-2:2022 requires the acquirer to define monitoring activities, their frequency, reporting, and corrective-action follow-up in the agreement, while the supplier supports those activities and operates its corrective-action process. Both parties reassess relevant changes and preserve the resulting records. The monitoring plan should state what is checked, who checks it, which evidence is accepted, when review occurs, and what triggers escalation after a nonconformity.

  • Monitor the agreed service and security measures, required reports and assurance, access, incidents, vulnerabilities, updates, findings, corrective actions, subcontractors, and upstream dependencies.
  • Set a scheduled review that fits the relationship, then add event triggers for material service, technology, location, ownership, personnel, subcontractor, threat, control, or obligation changes.
  • Increase review depth or frequency when evidence expires, performance degrades, findings repeat, corrective actions are late, or the business becomes more dependent on the supplier.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 requires compliance monitoring and enforcement, change and incident management, corrective-action tracking, risk reassessment, and review of the agreement.

ISO/IEC 27036-3:2023 standard page

Part 3 guides monitoring of supplier processes and work products, verification, vulnerability response, changes, provenance, and multi-layer dependencies.

ISO/IEC 27036 Supplier Monitoring

What should a monitoring review decide?

A review should decide whether the supplier and acquirer are meeting the agreement, whether the evidence covers the actual product or service and review period, whether risk has changed, and whether any finding needs correction, a control change, an agreement update, formal acceptance, or termination planning.

Do not equate receipt with review. Record the requirement tested, evidence and period, reviewer, result, limitation, finding severity, corrective-action owner and due date, approval, and next scheduled or event-driven review.

  • Compare current results with prior findings, service levels, incident history, risk assumptions, and the approved relationship scope.
  • Verify closure evidence for corrective actions instead of closing them from a supplier status statement alone.
  • Escalate persistent or material nonconformity through the agreement's enforcement and risk-acceptance process.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 identifies audit and risk reports, incident and change histories, corrective-action status, and approved agreement updates as relationship-management outputs.

ISO/IEC 27036-3:2023 standard page

Part 3 supports verification of supplier claims, monitoring of processes and work products, testing, maintenance records, vulnerability response, and component visibility.

ISO/IEC 27036 Supplier Monitoring

Which events should trigger an early review?

Trigger an early review after an incident, material vulnerability, missed service or security measure, expired or qualified assurance, major corrective-action delay, service or architecture change, new data use, access expansion, location change, merger or financial distress, new or changed subcontractor, end-of-support notice, regulatory change, or failed recovery or exit test.

The trigger should route to a named owner who can assess scope and risk, request evidence, update controls or terms, approve a time-bound exception, or begin replacement or termination. A calendar date alone does not handle fast-changing relationships.

  • Do not impose the same questionnaire and cadence on every supplier without regard to product or service risk.
  • Do not assume a current corporate certificate covers the exact service, location, period, controls, or upstream dependency in use.
  • State any mandatory monitoring or reporting interval from law, regulation, or contract separately from ISO/IEC 27036.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 ties monitoring to agreement compliance, risk, changes, incidents, corrective actions, and termination rather than one universal calendar interval.

ISO/IEC 27036-3:2023 standard page

Part 3 supports event-driven review of vulnerabilities, updates, business health, provenance, components, supplier processes, and supply-chain changes.

ISO/IEC 27036 Termination and Offboarding

What should supplier termination and offboarding cover?

Create a termination plan before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.

ISO/IEC 27036-2:2022 requires the supplier relationship agreement to contain a termination process and plan. At termination, the parties decide whether supply is cancelled, returned to the acquirer, or transferred to another supplier; maintain an asset inventory; agree asset return, transfer, destruction, or retention; remove access; communicate with affected parties; and confirm completion. The standard does not set a universal notice period, deletion deadline, or retention period; the agreement and applicable law supply those dates.

  • Before signing, define notice, sudden-termination handling, transition assistance, data format and export, asset handling, access removal, retention and deletion, surviving duties, evidence, acceptance, cost, timing, and escalation.
  • At exit, appoint an owner, assess any security reason for termination, activate continuity arrangements if sudden loss affects a critical service, and decide whether to cancel, bring the work back, or transfer it.
  • Close the relationship only after the parties verify the agreed outcome and an authorized owner approves any retained asset, unresolved action, or residual risk.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 requires termination planning in the agreement and specifies risk assessment, ownership, communication, asset inventory, transfer or cancellation, access removal, and completion agreement.

ISO/IEC 27036 Termination and Offboarding

What should the offboarding checklist verify?

Verify the service outcome and every access, asset, information, integration, and dependency affected by exit. The checklist should identify the responsible acquirer and supplier roles, due date, evidence, exception route, and completion approver for each item.

Return or deletion must follow the agreement and applicable retention, legal-hold, recordkeeping, and technical constraints. Distinguish active data, replicas, backups, logs, physical media, devices, source material, and records that must survive termination. Do not promise deletion where a binding duty requires retention.

  • Revoke named and shared accounts, privileged roles, physical access, keys, tokens, certificates, federation, remote support, network routes, and application integrations; rotate secrets exposed to the supplier.
  • Reconcile the asset inventory and document return, transfer, permitted retention, sanitization or destruction, chain of custody, and any required confirmation or disposal log.
  • Resolve or transfer open incidents, vulnerabilities, findings, corrective actions, tickets, changes, backups, continuity actions, intellectual-property material, and subcontractor obligations.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 makes an up-to-date asset inventory, agreed asset disposition, timely access removal, communication, execution, and completion confirmation part of termination.

ISO/IEC 27036 Termination and Offboarding

What evidence closes the relationship?

Retain the termination decision, risk assessment, current agreement and plan, communication record, named owner, asset inventory, access-removal results, transfer or cancellation acceptance, data export and integrity checks, return or disposal records, approved retention, exception decisions, and confirmation that the parties agree the supplied product or service has ended.

Evidence must match the actual scope. A generic deletion statement does not show which tenant, system, copy, backup, log, device, or subcontractor it covers. Record technical limits, scheduled expiry, continuing safeguards, and the person who accepted any remaining exposure.

  • Verify surviving confidentiality, audit, incident-cooperation, intellectual-property, warranty, retention, and deletion duties.
  • Do not let contract expiry automatically close operational access or open actions.
  • If termination is disputed or involves legal, regulatory, employment, insolvency, or evidence-preservation issues, obtain case-specific advice; ISO/IEC 27036 does not decide those rights.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 defines required termination activities and outputs but leaves case-specific legal rights and duties to the agreement and applicable law.

Page 2 of 2