Select references according to the supplier relationship, product or service being assessed. Record the edition and purpose of each source, and distinguish current guidance from historical material retained in an older assessment.

NIST supply-chain guidance

NIST SP 800-161 Rev. 1, Update 1 provides cybersecurity supply-chain risk management guidance for systems and organisations. The publication includes updates through November 1, 2024 and replaces the older 2015 reference used in earlier documentation. NIST publication record.

Use it to inform the relationship between organisational direction, procurement, product or service assessment and ongoing risk management. Its guidance needs to be applied to the actual scope and responsibilities of the relationship.

ISO/IEC 27036

The supplier-relationship series has four complementary parts:

PublicationFocus
ISO/IEC 27036-1:2021Overview and concepts for acquirers and suppliers.
ISO/IEC 27036-2:2022Requirements for managing information security in supplier relationships.
ISO/IEC 27036-3:2023Hardware, software and services supply-chain security guidance.
ISO/IEC 27036-4:2016Security guidance for cloud-service relationships.

Select the parts relevant to the relationship and read their scope. Security guidance for acquiring a cloud service should not be assumed to cover every aspect of operating the provider's security programme or business continuity.

Historical ISO 28002 reference

ISO 28002:2011 addressed the development of resilience in the supply chain. ISO lists it as withdrawn, with withdrawal recorded on June 19, 2024. It is retained here to explain references in earlier documentation, not presented as a current standard to adopt. ISO status and scope.

The earlier resilience-process illustration should be read in that historical context. A process diagram alone does not establish the current requirements applicable to a supplier or the suitability of a resilience programme.

Historical supply-chain resilience process: establish resources, define scope, identify and prioritise risks, treat them, then monitor and reassess the preceding decisions.
Redrawn historical resilience process associated with withdrawn ISO 28002:2011. This is retained as historical context, not current requirements. Open full-size diagram.

The historical sequence establishes resources, defines the supply chain and objectives, identifies risks, quantifies and prioritises them, executes treatment, and monitors the supply-chain environment. Monitoring feeds reassessment of the programme, scope, risk sources, exposure and management actions.

Connect references to working records

In CSFaaS, document the supplier's role and criticality, link the systems and risks it affects, and collect relevant assessment evidence. Record which obligations and editions informed the review, who owns the decision, and what changes trigger reassessment. This keeps a reference list connected to actual supplier-management work.