21/30429681 DC
BS ISO/IEC 27036-2. Cybersecurity. Supplier relationships Part 2. Requirements
| Označení normy: | 21/30429681 DC |
| Počet stran: | 46 |
| Vydáno: | 2021-09-09 |
| Status: | Draft for Comment |
21/30429681 DC
This standard 21/30429681 DC BS ISO/IEC 27036-2. Cybersecurity. Supplier relationships is classified in these ICS categories:
- 35.030 IT Security
This part of ISO/IEC 27036 specifies fundamental information security requirements for defining, implementing, operating, monitoring, reviewing, maintaining and improving supplier and acquirer relationships.
These requirements cover any procurement and supply of products and services, such as manufacturing or assembly, business process procurement, software and hardware components, knowledge process procurement, Build-Operate-Transfer and cloud computing services.
These requirements are intended to be applicable to all organizations, regardless of type, size and nature.
To meet these requirements, an organization should have already internally implemented a number of foundational processes, or be actively planning to do so. These processes include, but are not limited to, the following: business management, risk management, operational and human resources management, and information security.
