How to assess and gain confidence in your supply chain cyber security
Pages
Page 6 of 29
Step 2: Identify the key players in your organisation
Having the right people in place to support supply chain cyber security will help drive the changes required. Think of people within your organisation and consider:
-
Who do you need to convince to establish or improve assessment of supply chain cyber security?
Who is best placed to influence change and make decisions around investment and use of resources? For more information please refer to Report progress to the board.
-
Who is responsible for developing a new approach to assessing supply chain cyber security?
Ideally, this should be someone or a combination of people with supply chain and cyber security expertise, or with sufficient knowledge of cyber security practices that can be applied to the supply chain.
-
Who should be consulted during the development of this new approach?
Supply chain cyber security requires collaboration between multiple disciplines, such as IT security, procurement, risk management, legal, business stakeholders and more. Consider which teams in your company are involved in the supplier lifecycle that would be impacted by this activity and whether they could play a part in developing a new approach.
-
Who should be kept informed about the activity?
This will include people who do not directly contribute to the creation of the new approach but have an interest in or may be impacted by its progress. For example:
- members of the leadership team who you may report progress to
- colleagues that may have a role in implementing the new approach when established
- your suppliers who you will want to keep informed of any changes to security requirements and practices (for further information on who you should get involved, see ‘Who should be involved in supply chain cyber assurance activities?’, below).
Once you have identified the above, pitch to your influencers and decision makers on why they should invest in securing the supply chain, taking what you have learnt from Step 1. Remember to also seek input from those who may be affected.
Create terms of reference that you can use to initiate the change effort. Use these to contextualise what are the important cyber security objectives for your organisation and start to promote a culture of security within the supply chain, from senior leadership who need visibility of the problem, to the individual teams (organisation and supplier side) that need to work together to ensure that due diligence is carried out effectively.
Set up a governance process where security leadership meets with the board on a regular basis and articulates the organisational position with regards to supply chain cyber security to ensure that the supply chain cyber security challenges are well understood, and appropriate decision making is carried out.
Define a process with clear roles & responsibilities and criteria
Once you have identified the right people, you can create a process that works for your organisation to assess a supplier. Note that this may involve more people than those used to define the approach.
Typical stages might include:
- using questions to establish a supplier security profile for an acquisition
- confirming with suppliers the expected controls for its supplier security profile
- ensuring suppliers complete an assurance questionnaire to evaluate compliance with the controls
- working with the supplier to complete the supplier management plan
- ongoing reviews and assessment of supplier, as outlined in the supplier management plan
Likely roles (which may vary and overlap depending upon the organisation) that may be involved in assessing supply chain cyber security include:
| Role | Description |
|---|---|
| IT/Cyber Security | Have the technical expertise to advise on the supplier architecture and controls proposed, and advise on any mitigations required. Responsible for setting supply chain security standards and assurance activities required within the complete supply chain. Understand how the procurement fits into the organisation's wider technology plans and security programme. |
| Procurement | Ensures that supplier assurance practices are embedded within the acquisition process. |
| Risk Management | Set the risk management approach for the organisation, working to ensure any third-party activities follow standards. |
| Software Development | Understand all aspects of secure software development and can advise to ensure products delivered have vulnerabilities identified and addressed as early as possible. |
| IT Engineering | Evaluate the security in new hardware products and understand the configuration settings that should be applied. Of special interest (within the supply chain context) is evaluating components sourced from external sources. |
| Legal | Ensures that contracts include supply chain cyber security clauses, and resolution of contractual issues. |
| HR | Define and implement background checks and training policies to ensure individuals are trained in appropriate supply chain cyber security processes and procedures. |
| Business Owners | Originator/owner/end user of the acquisition request. Responsible for ensuring that the acquisition meets their needs and may play a part in defining the risk level that the acquisition might pose. |
| Leadership | Senior leadership have a role in providing appropriate direction and investment in cyber security resources for supply chain risk management. |
-
Step 2: Further reading
For more information on security governance, see the NCSC’s guidance on the governance of cyber risk.



