ISO/IEC 27035 & ISO/IEC 27036 Extended Control Assessment

Strengthen incident and third-party risk posture with independent validation.

Candid Meeting

What Are ISO/IEC 27035 and ISO/IEC 27036?

ISO/IEC 27035 and 27036 expand, rather than replace, the ISO/IEC 27001 methodology.

ISO/IEC 27035 and 27036 expand, rather than replace, the ISO/IEC 27001 methodology.

What Extended Control Set Assessments Prove

Incident handling controls validated through operational evidence.

SLA, escalation, and communication controls substantiated with proof.

Supplier access domains and governance boundaries justified through artifacts.

Third-party risk controls verified across onboarding, monitoring, and offboarding.

Why These Extensions Matter

Organizations that already maintain an ISO/IEC 27001-certified information security management system (ISMS) often face growing scrutiny around incident handling and supplier governance. An extended control assessment from Insight Assurance provides objective evidence that incident response processes and third-party oversight meet the deeper expectations set by ISO/IEC 27035 (for incident management) and ISO/IEC 27036 (for supplier relationships). 

By validating escalation paths, service-level agreements (SLAs), and governance boundaries, the assessment helps protect the business, earn stakeholder trust, and reduce the risk of costly breaches.

Key Benefits

What Insight Assurance Validates in Assessments

ISO/IEC 27035 Focus Areas

ISO/IEC 27036 Focus Areas

Common Evidence Artifacts Sampled

This evidence demonstrates that controls operate as designed across the entire incident and supplier-management lifecycles.

Why Choose Insight Assurance?

We help organizations assess their cloud security and privacy practices with independence, clarity, and technical depth.

Cloud-Focused Expertise

Our assessors understand the nuances of multi-cloud, hybrid environments, and shared responsibility models.

Independent Evaluation

We act solely as third-party auditors, not implementers or advisors.

In-House Professionals

All assessments are conducted by our internal, certified audit team.

AI-Enhanced Workflows

Fieldguide helps us streamline document collection and control mapping.

Clear Reporting

We deliver findings tailored to both technical and executive audiences.

Big 4-Trained Auditors

Seasoned auditors drawn from Big 4 backgrounds bring global reach, transparent workflows, and a 24-hour SLA on responses.

Validate Your Incident Management Controls

Elevate stakeholder assurance and meet escalating regulatory expectations. Contact Insight Assurance to schedule your ISO/IEC 27035 & 27036 extended control assessment today.

Let's Talk Compliance

Share a few details and our team will be in touch shortly to schedule a friendly, no-pressure conversation—no obligations, just answers.

Insight Assurance needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at any time. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, please review our Privacy Policy.