Step 2: Embed cyber security controls throughout the contract's duration
Consider cyber security through every step of the contract lifecycle:
If a decision has been made to outsource to an external supplier, determine whether a cyber security risk assessment is needed and to what level, based on the risk criteria you have set.
During supplier selection, conduct due diligence, assess each supplier’s ability to meet your cyber security controls and ensure this is a part of the decision-making process for selection.
When awarding a contract, stipulate compliance with necessary cyber security controls in the supplier contract and agree this with the supplier.
Whilst in contract with the supplier, ensure supplier security provisions are effective and meeting expectations, incidents are managed appropriately and there is an up-to-date awareness of evolving threats and vulnerabilities.
When terminating a contract, make sure you regain control of your assets and shut down any unauthorised or unintended access to your information and systems.