What is the ISO 27036 standard?
ISO 27000 is a series of information security standards developed and published by the International Organization for Standardization (ISO), which provides a globally recognized framework for best practices in developing the Information Security Management System (ISMS).
The ISO 27036 standard is divided into four parts and is one of the standards belonging to the ISO 27000 family, referring to Information security for supplier relationships, it offers guidance on the assessment and treatment of information risks involved in the acquisition of goods and services from suppliers.
Part of ISO 27000, referring to Information security for supplier relationships, which offers guidance on the assessment and treatment of the information risks involved in the acquisition of goods and services from suppliers.
Organization and uses of ISO 27036
How is the standard divided?
The ISO/IEC 27036 standard is divided into the following four parts:
- ISO/IEC 27036-1:2014: Covers the general description and main concepts. It serves as an introduction to the four parts of this standard, providing general information on the regulatory background (ISO 27000, IT – Security techniques – Information security management systems – Overview and vocabulary), and introducing key terms and concepts, including risks, in relation to information security in supplier relationships.
- ISO/IEC 27036-2:2014: Specifies the fundamental information security requirements relating to business relationships between suppliers and acquirers. The recommended control measures cover various aspects of governance, business management, and information security management (enabling organizational projects, planning the supplier relationship, relationship agreements, supplier relationship management, etc.).
- ISO/IEC 27036-3:2013: Provides the guidelines for ICT supply chain security. It sets out guidance for both suppliers and acquirers on managing information security risks related to the supply chain (malware, counterfeit products, organizational risks, integration of risk management with system and software life cycle processes, etc.).
- ISO/IEC 27036-4:2016: Describes the guidelines for the security of cloud services. It provides cloud service customers and providers with guidance on the information security risks associated with the use of cloud services and the effective management of those risks through the implementation of specific controls for their mitigation.
Where is ISO 27036 applied?
The standard applies to business relationships between buyers and suppliers of various goods and services, such as:
- Supply of hardware, software, and ICT services, including telecommunications and Internet services.
- Outsourcing of cloud computing services.
- Other services such as security guards, cleaners, courier services, equipment maintenance, consulting and specialized advisory services, etc.
- Custom products and services where the acquirer specifies the requirements and usually has an active role in the product design.
- Utilities such as electricity, fuels, and water.
Phases of ISO 27036:
Guidelines are given for the detection and assessment of the information risks involved in the acquisition of goods and services and the implementation of the controls necessary for their mitigation, throughout the entire life cycle or phases of the relationship between acquirers and suppliers:
What is the life cycle of the relationship?
The ISO 27036 life cycle is made up of several phases:
- Cost-benefit analysis, comparison of in-house development or outsourcing options, or a mix of both.
- Definition of requirements.
- Selection, evaluation, and contracting with suppliers.
- Application of the supply agreements.
- Operation: management and supervision of relationships, compliance, incidents and changes, etc.
- Updating upon possible contract renewal, with review of terms and conditions, performance, issues, work processes, etc.
- End of the business relationship.
Information security risks:
The situations where information security is compromised are classified into:
- The acquirer’s dependence on suppliers.
- Access to and protection of third-party information assets.
- Shared responsibilities regarding information security with respect to compliance with policies, standards, laws, regulations, contracts, and other information security commitments/obligations.
- Acquirer-supplier coordination to adapt or respond to new information security requirements.
Information security controls:
The security controls relating to information must be carried out in:
- The preliminary analysis of risks, controls, costs, and benefits associated with maintaining adequate information security.
- The creation of shared strategic objectives to align the buyer and supplier on information security.
- The specification of information security requirements: requiring suppliers to comply with the ISO/IEC 27001 standard in contracts, service level agreements, etc.
- Security management procedures: risk analysis, security design, incident management, business continuity plans, among others.
- The responsibility for protecting critical information assets (security logs, audit logs, evidence, etc.).
- The right to audit and compliance, with penalties or liabilities in the event of non-compliance or incentives in the event of full compliance.
At GlobalSuite Solutions we offer the necessary help and advice for the implementation of your Information Security Management System (ISMS) based on the requirements of ISO 27001.
In addition, we have the GlobalSuite® software, entirely developed by our team, which allows the implementation, management and maintenance of the requirements demanded by the ISO 27001 standard in all types of organizations and sectors.
