Skip to main content
Guidance

How to assess and gain confidence in your supply chain cyber security

Practical steps to help medium to large organisations gain assurance about the cyber security of their organisation's supply chain.

Pages

Page 6 of 29

Step 2: Identify the key players in your organisation

Having the right people in place to support supply chain cyber security will help drive the changes required. Think of people within your organisation and consider:

  • Who do you need to convince to establish or improve assessment of supply chain cyber security?

    Who is best placed to influence change and make decisions around investment and use of resources? For more information please refer to Report progress to the board.

  • Who is responsible for developing a new approach to assessing supply chain cyber security?

    Ideally, this should be someone or a combination of people with supply chain and cyber security expertise, or with sufficient knowledge of cyber security practices that can be applied to the supply chain.

  • Who should be consulted during the development of this new approach?

    Supply chain cyber security requires collaboration between multiple disciplines, such as IT security, procurement, risk management, legal, business stakeholders and more. Consider which teams in your company are involved in the supplier lifecycle that would be impacted by this activity and whether they could play a part in developing a new approach.

  • Who should be kept informed about the activity?

    This will include people who do not directly contribute to the creation of the new approach but have an interest in or may be impacted by its progress. For example:

    • members of the leadership team who you may report progress to
    • colleagues that may have a role in implementing the new approach when established
    • your suppliers who you will want to keep informed of any changes to security requirements and practices (for further information on who you should get involved, see ‘Who should be involved in supply chain cyber assurance activities?’, below).

Once you have identified the above, pitch to your influencers and decision makers on why they should invest in securing the supply chain, taking what you have learnt from Step 1. Remember to also seek input from those who may be affected.

Create terms of reference that you can use to initiate the change effort. Use these to contextualise what are the important cyber security objectives for your organisation and start to promote a culture of security within the supply chain, from senior leadership who need visibility of the problem, to the individual teams (organisation and supplier side) that need to work together to ensure that due diligence is carried out effectively.​

Set up a governance process where security leadership meets with the board on a regular basis and articulates the organisational position with regards to supply chain cyber security to ensure that the supply chain cyber security challenges are well understood, and appropriate decision making is carried out.

Define a process with clear roles & responsibilities and criteria

Once you have identified the right people, you can create a process that works for your organisation to assess a supplier. Note that this may involve more people than those used to define the approach.

Typical stages might include:

  • using questions to establish a supplier security profile for an acquisition
  • confirming with suppliers the expected controls for its supplier security profile
  • ensuring suppliers complete an assurance questionnaire to evaluate compliance with the controls
  • working with the supplier to complete the supplier management plan
  • ongoing reviews and assessment of supplier, as outlined in the supplier management plan

Published

Reviewed

Version

1.0