Skip to main content
Guidance

How to assess and gain confidence in your supply chain cyber security

Practical steps to help medium to large organisations gain assurance about the cyber security of their organisation's supply chain.

Pages

Page 10 of 29

Stage 2a: Prioritise your organisation's 'crown jewels'

Determine the critical aspects in your organisation that you need to protect the most (your ‘crown jewels’), taking into consideration potential threats, vulnerabilities, impact and your organisation’s risk appetite.
  • Expected outputs from Stage 2a.

    • A clear understanding of the most critical aspects of your organisation, with criteria for determining what assurances you need from suppliers to be able to protect them.

 

To do this, it’s useful to consider the resources each supplier has access to. For example:

  • Will the supplier have access to personally-identifiable/commercially-sensitive data?
  • Where will the supplier be processing and storing the organisation’s data and information?
  • Will the supplier have access to major or business critical assets?
  • Will the supplier have access and/or connection to the organisation's network with additional privileges?
  • Does the supplier have any links to governments or organisations that might be hostile to your sector?

You can also consider the effects of a possible breach:

  • Is the supplier a single point of failure? What is the supplier doing for you?
  • Would a breach via the supplier adversely impact the organisation’s business operations and/or processes?
  • Would a breach via the supplier adversely impact the organisation’s reputation?
  • Would a breach via the supplier cause significant financial and/or legal, regulatory or contractual consequences?
  • Would a breach affect the safety of your staff or customers?

You can use these criteria to define a set of supplier security profiles, and to tier them from low to high (see Stage 2b. Create key components for your approach). The criteria you use will vary depending on the nature of your sector or organisation.

Stage 2a: Further reading


Published

Reviewed

Version

1.0