How to assess and gain confidence in your supply chain cyber security
Pages
Page 11 of 29
Stage 2b: Create key components for your approach
Create a repeatable, consistent approach for assessing the cyber security of your suppliers.
Expected outputs from Stage 2b
- A set of ‘security profiles’, with the minimum cyber security requirements each profile is expected to meet.
- Questions to determine the security profile of each supplier.
- Artefacts required to assess each supplier’s requirements.
- A supplier security management plan to track compliance to cyber security requirements.
- Standard contractual clauses (relating specifically to cyber security) to insert into contracts.
Step 1: Create a set of security profiles
Using your organisation’s ‘crown jewels’ identified in Step 2a, create a number of tiered supplier security profiles. Each profile should represent an increasing scale of impact, which can be assigned to each of your suppliers.
In the example below, we’ve created a 3-tiered model, which is based on the levels of impact to reputation, business operations/processes and financial/legal consequences. Of course, your own criteria should be based on what is important to your organisation, and you may choose to use additional (or different) categories. You can then use the profiles to stipulate the scale of protection that you expect your supplier to put in place for the engagement.
We recommend you define between 3 and 5 profiles; this will ensure your levels are neither too broad nor too prescriptive.
Note:
In reality, there will be crossover between what is deemed low, medium and high impact. You will need to tailor the risk levels and subsequent minimum security requirements dependent upon the activity being undertaken or the industry or environment in which they are to be used. It will not always be clear cut, and there may be a degree of subjectivity.
Example supplier security profiles (3-tier model)
| Tier | Security profile | Description |
|---|---|---|
| 1 | LOW IMPACT from a supply chain-related cyber attack or data breach | This LOW impact profile assumes:
This may mean that procurement requires:
|
| 2 | MODERATE IMPACT from a supply chain-related cyber attack or data breach | This MEDIUM impact profile assumes:
From a cyber security perspective, this may mean that procurement requires:
|
| 3 | HIGH IMPACT from a supply chain-related cyber attack or data breach | This HIGH impact profile assumes:
From a cyber security perspective, this may mean that procurement requires:
|
Step 2: Determine the security profile for each supplier
You can use a series of questions (based on the considerations within Step 2a) to triage each supplier, and determine which of the security profiles should be assigned.
Step 3. Define the minimum cyber security requirements for each security profile
For each security profile, determine the minimum cyber security requirements that each supplier must adhere to. Map out the necessary requirements with increasing levels of stringency as the risk level increases, ensuring that they are proportionate to the risk posed.
The following example shows the security requirements for the 3-tiered model described earlier. Note that:
- it starts with a baseline defining the minimum requirements across all tiers (which in this case is Cyber Essentials certification)
- it then defines additional requirements required at subsequent tiers in proportion to the risks posed
- this is just an example; you’ll almost certainly need to tailor these requirements to reflect your own organisation, the sector you operate in, and your risk appetite
| Tier | Baseline security requirements Controls may be moved between risk categories |
|---|---|
| 1: LOW impact | Cyber Essentials scheme certification (or equivalent) |
| 2: MODERATE impact | All Tier 1 requirements plus:
|
| 3: HIGH impact | All Tier 2 requirements plus:
|
When defining cyber security requirements:
Consider creating different sets of requirements for different supplier sizes to ensure your requests are realistic, pragmatic, and proportionate to the risk. NCSC’s guidance on cyber security for micro, small, medium and large organisations may be useful here.
Consider creating different sets of requirements for different supplier types. Some organisations find it helpful to have a standard set of controls, and then define additional sets as different goods and services are purchased. NCSC’s guidance on cloud security, software as a service, bulk personal data protection and defending software build pipelines can help you with this, as well as the NCSC’s Product Development Principles.
Here are some categories that you should consider including within your standard control set:
- Access Control What information and assets could suppliers have access to, and what level of access is provided (in particular privileged account access)? What policy exists for control of remote access to networks and systems?
- Application Development and Support Does the supplier have a documented SDLC (software development life cycle) process which provides assurance about the development and support for products and services?
- Business Continuity and Disaster Recovery Does the supplier have a defined and regularly tested process for IT Business Continuity and Corporate Disaster recovery?
- Change Management Are methods in place to control how changes are authorised, tested and securely deployed by authorised personnel?
- Data and Information Security Is the supplier able to describe security measures in place for mobile devices, use of personal devices, data loss prevention, security monitoring, erasure and disposal, protection of data in transit and at rest?
- Governance and Policy Does the supplier have a strong security policy for management of IT equipment, covering employee responsibilities, access to information assets and user account / password management, and management of removable media?
- Incident Management Does a defined and implemented policy including detection, resolution and recovery exist?
- Independent Testing and Assurance Is the supplier able to describe what independent testing is carried out on corporate environments, critical security controls, and in underpinning product assurance?
- Monitoring Is monitoring in place to assess access to privileged accounts and services, networks, authorised software, data loss prevention and regular log management?
- Personnel Security Does the supplier provide training on information security and vetting of staff? Do roles exist for dedicated information security staff to set and enforce standards?
- Physical Security Is the supplier able to describe how physical security is implemented to protect corporate premises and sensitive areas?
- Remote Connectivity Is the supplier able to describe how they secure and encrypt any remote connections to your network?
- Supply Chain Management How well are the information security risks within the wider supply chain managed? Does the supplier risk manage its own supply chain?
- Vulnerability Management and Patching Are processes in place to be informed of vulnerabilities present within equipment and software, along with a timely and secure patching policy used to remedy?
Other considerations that may influence your expectations could be:
- The nature of your sector or industry For example, regulatory requirements (such as GDPR), or tolerance levels for a safety critical industry may apply.
- Existing organisational standards and frameworks You may wish your suppliers to adopt the same or similar standards for cyber security frameworks as your organisation. For example, if your organisation already uses ISO 27001, it may want suppliers to use the same or demonstrate equivalency. Consideration about the possible threats to your organisation might supersede existing standards, you do not have to place reliance on them and can adapt them to use to best advantage. It should be noted that compliance against standards and frameworks does not necessarily provide security.
- Size of the supplying organisation If the supplier is small, it may be pragmatic to accept that what they have in place might be different to controls in a much larger organisation. This could be considered in conjunction with the risk levels of the acquisition to tailor the control set accordingly.
You may require your supplier to follow similar or equivalent standards to your own organisation, or you may operate in a regulated field which requires specific practices to be followed. Some common standards, certifications and regulations are listed below:
| Industry standard | Description |
|---|---|
| Cyber Assessment Framework | The NCSC has published 14 high-level security principles with which all OES (operators of essential services) must implement, in the form of the CAF. The CAF breaks each principle down into specific outcomes, which are then further broken down into IGPs (indicators of good practice). |
| Cyber Essentials and Cyber Essentials Plus | Cyber Essentials is an NCSC-backed certification scheme designed to show an organisation has a minimum level of protection in cyber security through annual assessments to maintain certification. |
| GDPR | General Data Protection Regulation is a data protection legal framework that applies to organizations operating within the EU (and those worldwide that target individuals in the EU). |
| ISO 27001 | An internationally recognised standard that, once certified, requires that the organisation complies with the Information Systems Management Security policy covered within this standard. |
| ISO 28000 | An internationally recognised standard that, once certified, requires that the organisation complies with the requirements of a security management system covered within this standard, including aspects relevant to the supply chain. |
| NIST 800-53 | A catalogue of security and privacy controls published in the US by the National Institute of Standards and Technology. |
| PCI DSS | Payment Card Industry Data Security Standard. Specific to organisations that accept credit card payments online. |
Step 4: Decide how to assess your suppliers
There are several ways to assess your supplier’s cyber security standards. The approach taken is likely to be constrained by how much time and resource you have available to carry out an assessment. For most organisations, a combination of techniques should be considered to allow the cross section of suppliers to be assessed.
A holistic view of the supplier should be established, including:
- where it operates from (and what laws and regulations apply in that region)
- where research and development work is carried out
- where data is held
- whether nation states have any influence on the supplier
The following table summarises common methods to assess a supplier's cyber security standards.
| Assessment Method | Considerations |
|---|---|
| Question based survey | A simple and repeatable method of assessment. Suppliers may be able to answer questions in multiple ways, and may lean towards painting a better picture than might be established through face-to-face or video conversation. Prospective suppliers will most likely require further investigation by the organisation. |
| Interviews | Time consuming and also requiring a specialist resource to carry out. Information gained is probably of higher value than a question based survey. Areas of concern can be instantly followed up, in order to fully establish the risk. |
| Site visit | Allows the organisation to see a supplier’s premises, understand how it operates, and interact with the right people to be able to obtain information. On-site visits can be expensive and time-consuming, particularly if the supplier is based overseas. However, visiting the supplier shows that you are serious about the supplier’s performance and it both helps to reinforce a positive supplier relationship and can allow you to help address issues with poorly performing suppliers. |
| Independent assessment / Certification | Outsourcing of assessments to an authorised body will increase the cost and potentially limit the assessment to the standard question set. The benefits of this approach are that it is more scalable and easier to compare suppliers. Examples of independent assessment methods include Cyber Essentials Plus, SOC 2 reports and ISO 27001. |
| Automated assessment | There are commercial tools on the market that can automatically assess an organisation, which could be used in conjunction with the above assessment techniques to regularly assess a supplier. These tools are quick and easy to set up and have the advantage of providing near continuous assessments. However, the results will need interpreting using a skilled person and will have cost implications. |
Assessing your suppliers comes at a cost, so you need to consider:
- What is their security profile? Clearly, you should spend more time monitoring suppliers that pose a higher risk to your organisation.
- Does the ability to audit the supplier exist within the contract? For example, is the supplier required to inform you if a significant change has occurred, or if there has been a breach?
- What type of assessment is required (on site, verbal, form-based, outsourced)? This will consume your resources, and your supplier will need time to respond to any assessments. If resources are limited, this will restrict how often you can assess your suppliers.
1. Communicate requirements as early as possible.
If you are establishing a new supplier relationship, let them know in advance what your standard minimum security requirements are, and how they vary for contracts at different risk levels. This can be shared as early as the Invitation to Tender. Many organisations even publish these on their websites or on other communication channels specifically shared with suppliers.
If you are introducing new security requirements to existing suppliers, explain why you are making the change and what this will mean for suppliers from this point. Give them plenty of notice before implementing the changes and allow opportunities to seek clarifications.
2. Seek evidence from your suppliers.
Ask for evidence to check that suppliers are compliant with your cyber security requirements, rather than taking their word for it. Evidence-based assurance should be maintained throughout the contract duration and not just at onboarding stage. This can be achieved in several ways, as described in Step 4 above.
3. Mandate compliance of minimum cyber security requirements in your supplier contracts.
Stipulating your requirements into your supplier contract formalises the supplier’s responsibility to meet cyber security requirements. The contract should also define requirements to subcontractors, and penalties if said requirements are not met or complied with. This achieves two things:
- it deters immediate suppliers from breaching contract
- it places responsibility on the immediate supplier to ensure their suppliers also adhere to the same requirements
Step 5: Plan for non-compliance
Suppliers may not always fully comply with your requirements. However, you may still wish to work with them, whilst they rectify any shortfalls. Planning for this is useful as you can articulate the expected frequency and nature of continued assessments, to ensure an accurate and up-to-date picture.
Have a discussion with the potential suppliers to show them where they have not met your requirements. Make recommendations on what they need to do to improve their cyber risk position, and discuss if this is possible in the given timeframe. Create a security management plan that defines the controls that the supplier will need to have in place within a specified schedule. This may include:
- controls met and not met
- actions required to resolve
- timescales
- last assessment date
- next assessment date
- assessment type (for example site visit, questionnaire, pen test)
- assessment outcome
Step 6: Create contractual clauses
Create a standard set of clauses to include within your contract agreements to cover a variety of likely scenarios for your organisation. These can then be easily inserted into the process as part of an acquisition.
Common arrangements that are put into the contracts include:
- Ensuring that any subcontractors employed by the supplier conduct the same levels of cyber security protection as per the supplier itself. This may include restrictions on organisations or regions that may be subcontracted to, or where data is held and notification in the case a subcontractor changes.
- Incident management response and notification timeframes for responding to a breach, along with provision of support to the organisation to find the root cause.
- Staff clearances expected and due diligence to be conducted, possibly organisational approval as to which supplier personnel have access to the systems.
- Ability to audit your supplier and expected frequency of audits.
- Whether insurance for cyber security incidents is required.
- Disclosure of previous component vulnerabilities, cyber incidents or data breaches.
- General cyber security controls to be adhered to (levels of encryption required, end user devices allowed, data destruction, identity and audit controls).
- Agreement for length of time the equipment will be supported and maintained to avoid equipment falling out of support.
- Data management including what information can be passed onto a third party supplier. Only necessary data may be transferred out of the organisational network and must be protected via authentication and encryption. Will data be segregated if held on a supplier platform?
- Ability to invoke a break clause in the contract if the supplier security does not meet expected standards.
- Any other stipulations that clearly define the organisation’s and supplier’s responsibilities in cyber assurance activities.
Stage 2b: Further reading
-
The NCSC's Supplier assurance questions
The NCSC has published guidance on supplier assurance questions to help you gain confidence in your suppliers' cyber security.
-
The NCSC's Introduction to identity and access management
Introduction to identity and access management provides a primer on the essential techniques, technologies and uses of access management.
-
Further information on how to manage risk for specialist categories can be found below:
- Cloud security guidance: How to choose, deploy and use cloud services securely.
- Lightweight approach to cloud security: How to carry out a rapid but reliable assessment of cloud services.
- Protecting bulk personal data: 15 good practice measures for the protection of bulk data held by digital services.
- Defending software build pipelines from malicious attack: Why your build pipeline is one of the foundations of your system security.



