ISO/IEC 27036-3:2013 - Guidelines for ICT supply chain security Scope & purpose: this part of the standard guides both suppliers and acquirers of ICT goods and services on information security risk management relating to the widely dispersed and complex supply chain, including risks such as malware and counterfeit products plus ???organizational risks???, and the integration of risk management wit