- ISMS context and audit expectations that typically require supplier assurance evidence.
References and citations
- Baseline controls that ISO 27036 expands with supplier lifecycle requirements and guidance.
- Overview and concepts: supplier relationship types, risks, interdependencies, and indirect suppliers.
- Normative requirements; defines supplier relationship life cycle processes and monitoring/enforcement expectations.
- Guidance for hardware, software, and services supply chain security used when suppliers have deeper product or component risk.
- Cloud services supplier relationship guidance across the lifecycle and supply chain.