This is misleading.
ISO standards dictate that a company should have certain processes in place. Like quality assurance, customer satisfaction, continuous improvement, ect. They do not specify individual processes or procedures to the company. They just lay out which structures should exist in an ISO compliant company. It is up to the company to develop processes and procedures that fulfill those structures.
The specific standards that are a "silver bullet" (as the author puts it) are NIST 800-171 "DFARS", ITAR, AS9100, NADCAP, and other smaller (yet equally significant) manufacturer-specific specifications that get flowed down the supply-chain on an as-needed basis.
So there is no ambiguity. If a supplier does business with a diverse enough client base in aerospace they will almost certainly have overlapping systems in place to protect against these things. Without pretty much all of the specifications I listed above, a supplier would not legally limited in what they are allowed to possess and produce.