Skip to main content
Guidance

How to assess and gain confidence in your supply chain cyber security

Practical steps to help medium to large organisations gain assurance about the cyber security of their organisation's supply chain.

Pages

Page 11 of 29

Stage 2b: Create key components for your approach

Create a repeatable, consistent approach for assessing the cyber security of your suppliers.

  • Expected outputs from Stage 2b

    • A set of ‘security profiles’, with the minimum cyber security requirements each profile is expected to meet.
    • Questions to determine the security profile of each supplier.
    • Artefacts required to assess each supplier’s requirements.
    • A supplier security management plan to track compliance to cyber security requirements.
    • Standard contractual clauses (relating specifically to cyber security) to insert into contracts.

Note:

In reality, there will be crossover between what is deemed low, medium and high impact. You will need to tailor the risk levels and subsequent minimum security requirements dependent upon the activity being undertaken or the industry or environment in which they are to be used. It will not always be clear cut, and there may be a degree of subjectivity.

Example supplier security profiles (3-tier model)

TierSecurity profileDescription
1LOW IMPACT from a supply chain-related cyber attack or data breach

This LOW impact profile assumes:

 

  • no or limited reputational damage
  • no or limited impact to business operations and/or processes
  • no or minimal financial/legal consequences

This may mean that procurement requires:

 

  • third party access to publicly disclosable information only
  • third party access (or no access) to minor assets only
  • no third party access/connection to organisation's network
2MODERATE IMPACT from a supply chain-related cyber attack or data breach

This MEDIUM impact profile assumes:

 

  • some reputational damage
  • some impact to business operations and/or processes
  • some financial/legal consequences

From a cyber security perspective, this may mean that procurement requires:

 

  • third party access to information containing personally identifiable data
  • third party access to major assets (standard access only)
  • third party access/connection to organisation's network
3HIGH IMPACT from a supply chain-related cyber attack or data breach

This HIGH impact profile assumes:

 

  • high reputational damage
  • high impact to business operations and/or processes
  • high financial/legal consequences

From a cyber security perspective, this may mean that procurement requires:

 

  • third party access to or processing of personally identifiable/commercially sensitive data
  • third party access to major assets with privileged access, or business critical assets
  • third party access/connection to organisation's network with additional privileges





Stage 2b: Further reading


Published

Reviewed

Version

1.0