Information technology. Security techniques. Information security for supplier relationships - Guidelines for security of cloud services

Information technology. Security techniques. Information security for supplier relationships - Guidelines for security of cloud services

Regular price
£232.00
Sale price
£232.00
Regular price
£116.00
Sold out
Unit price
per 

What is ISO/IEC 27036-4 - Guidelines for security of cloud services about?  

ISO/IEC 27036-4 provides cloud service customers and cloud service providers with guidance on 

  • Gaining visibility into the information security risks associated with the use of cloud services and managing those risks effectively, and 
  • Responding to risks specific to the acquisition or provision of cloud services that can have an information security impact on organizations using these services. 

The scope of ISO/IEC 27036-4 is to define guidelines supporting the implementation of information security management for the use of cloud services. 

Note 1: ISO/IEC 27036-4 does not provide guidance on how a cloud service provider should implement, manage and operate information security. Guidance on those can be found in ISO/IEC 27002 and ISO/IEC 27017. 

Note 2: ISO/IEC 27036-4 does not include business continuity management/resiliency issues involved with the cloud service. ISO/IEC 27031 addresses business continuity. 

Who is ISO/IEC 27036-4 - Guidelines for security of cloud services for? 

ISO/IEC 27036-4 on guidelines for security of cloud services is useful for: 

  • Organizations that acquire or supply cloud services. 
  • Cloud service provider 
  • Cloud service customers 
  • Overall supply chain 
  • Information technology industry 

Why should you use ISO/IEC 27036-4 - Guidelines for security of cloud Services? 

ISO/IEC 27036-4 provides guidance on information security to cloud service customers and cloud service providers. Its application should result in 

  • Increased understanding and definition of information security in cloud services, 
  • Increased understanding by the customers of the risks associated with cloud services to enhance the specification of information security requirements, and 
  • Increased ability of cloud service providers to provide assurance to customers that they have identified risks in their service(s) and associated supply chains and have taken measures to manage those risks. 

ISO/IEC 27036-4 is intended primarily for risk owners in cloud service customers, who finally accept the use of the cloud service, and the individual accountable for the cloud service provided by the cloud service provider. The guidance is primarily focused on the initial link of the first cloud service customer and cloud service provider, but the principal steps should be applied throughout the supply chain, starting when the first cloud service provider changes its role to being a cloud service customer and so on.  

The manner in which this change of roles is repeated and the manner in which the same steps are repeated for each new cloud service customer-cloud service provider link in the chain are central to ISO/IEC 27036-4.  

By following the guidance contained within ISO/IEC 27036-4, it should be possible to have a seamless linkage of information security priorities visible across the supply chain. Information security concerns related to supplier relationships cover a broad range of scenarios. Organizations that wish to improve trust within their cloud service provision should define their trust boundaries, evaluate the risk associated with their supply chain activities, and then define and implement appropriate risk identification and mitigation techniques to reduce the risk of vulnerabilities being introduced through their cloud service provision supply chain.