- ISMS audit context where supplier assurance evidence is commonly required.
References and citations
- Baseline supplier relationship controls; ISO 27036 provides more detailed lifecycle guidance.
- Overview and concepts: types of supplier relationships, risks, interdependencies, and indirect suppliers.
- Normative requirements; defines supplier relationship life cycle processes and compliance monitoring and enforcement expectations.
- Guidelines for hardware, software, and services supply chain security, including deeper life cycle practices and software bill of materials context.
- Guidelines for security of cloud services across acquisition lifecycle and supply chain links.