ISO/IEC 27036-1:2021
ISO/IEC 27036-1:2021 is the overview and concepts part of the supplier-relationships series, the implementation guidance behind the supplier controls of ISO/IEC 27002. Clause 5 sets out why organizations use suppliers, the types of relationship (products, services with the location-dependent access patterns of Table 2, the ICT supply chain of successive acquirer and supplier tiers, cloud computing as a multi-supplier and multi-tenant relationship), the information security risks and threats of supplier relationships (shared responsibility, absent or weak management, insufficient communication, geographic and cultural differences, product risks of security function, quality, IP, authenticity and warranty), how both parties assess and treat those risks with access, quality and assurance controls written into the agreement and with transparency or, failing that, selection criteria, and the ICT supply chain considerations (acceptance criteria, an organization-wide acquisition system with requirements, pre-acquisition risk assessment, negotiated agreements with audit rights and continuous monitoring). Clause 6 explains the series: part 2 requirements, part 3 ICT supply chain guidance, part 4 cloud service guidance. Guidance, not certifiable.
ISO/IEC 27036-1:2021 is a compliance framework from International with 2 domains and 13 controls. The largest domains are Clause 5: Problem definition and key concepts – ISO/IEC 27036-1:2021 (8 controls), Clause 6: Overall ISO/IEC 27036 structure and overview – ISO/IEC 27036-1:2021 (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (2)
Clause 5: Problem definition and key concepts – ISO/IEC 27036-1:2021
| Code | Title |
|---|---|
| iso-iec-27036-1-2021::5.1 | Motives for establishing supplier relationships |
| iso-iec-27036-1-2021::5.2.1 | Supplier relationships for products |
| iso-iec-27036-1-2021::5.2.2 | Supplier relationships for services |
| iso-iec-27036-1-2021::5.2.3 | ICT supply chain |
| iso-iec-27036-1-2021::5.2.4 | Cloud computing |
| iso-iec-27036-1-2021::5.3 | Information security risks in supplier relationships and associated threats |
| iso-iec-27036-1-2021::5.4 | Managing information security risks in supplier relationships |
| iso-iec-27036-1-2021::5.5 | ICT supply chain considerations |
Clause 6: Overall ISO/IEC 27036 structure and overview – ISO/IEC 27036-1:2021
| Code | Title |
|---|---|
| iso-iec-27036-1-2021::6.1 | Purpose and structure of ISO/IEC 27036 |
| iso-iec-27036-1-2021::6.2 | Overview of ISO/IEC 27036-1: Overview and concepts |
| iso-iec-27036-1-2021::6.3 | Overview of ISO/IEC 27036-2: Requirements |
| iso-iec-27036-1-2021::6.4 | Overview of ISO/IEC 27036-3: Guidelines for ICT supply chain security |
| iso-iec-27036-1-2021::6.5 | Overview of ISO/IEC 27036-4: Guidelines for security of cloud services |
What is ISO/IEC 27036-1:2021 and who does it apply to?
ISO/IEC 27036-1:2021 is a compliance framework from International with 2 domains and 13 controls. ISO/IEC 27036-1:2021 is the overview and concepts part of the supplier-relationships series, the implementation guidance behind the supplier controls of ISO/IEC 27002. Clause 5 sets out why organizations use suppliers, the types of relationship (products, services with the location-dependent access patterns of Table 2, the ICT supply chain of successive acquirer and supplier tiers, cloud computing as a multi-supplier and multi-tenant relationship), the information security risks and threats of supplier relationships (shared responsibility, absent or weak management, insufficient communication, geographic and cultural differences, product risks of security function, quality, IP, authenticity and warranty), how both parties assess and treat those risks with access, quality and assurance controls written into the agreement and with transparency or, failing that, selection criteria, and the ICT supply chain considerations (acceptance criteria, an organization-wide acquisition system with requirements, pre-acquisition risk assessment, negotiated agreements with audit rights and continuous monitoring). Clause 6 explains the series: part 2 requirements, part 3 ICT supply chain guidance, part 4 cloud service guidance. Guidance, not certifiable. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 27036-1:2021 actually require?
ISO/IEC 27036-1:2021 has 13 controls organised across 2 domains. The largest domains are Clause 5: Problem definition and key concepts – ISO/IEC 27036-1:2021 (8 controls), Clause 6: Overall ISO/IEC 27036 structure and overview – ISO/IEC 27036-1:2021 (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 27036-1:2021 do I already cover?
ISO/IEC 27036-1:2021 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement ISO/IEC 27036-1:2021?
Start your ISO/IEC 27036-1:2021 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27036-1:2021 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 13 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required