Skip to main content
Guidance

How to assess and gain confidence in your supply chain cyber security

Practical steps to help medium to large organisations gain assurance about the cyber security of their organisation's supply chain.

Pages

Page 16 of 29

Step 4: Report progress to the board

In Stage 2 Develop an approach to assess supply chain cyber security, you agreed the appropriate governance structure, the roles and responsibilities to implement the approach, and defined a clear process with criteria for decision making. It is important to uphold that governance to ensure that cyber security practices introduced remain relevant and are ultimately meeting the objective to help secure the supply chain.

Define success criteria and metrics for reporting to the board, with a consistent method and frequency so the board have visibility of the risk levels. Some reporting metrics that may be considered include:

  • What % of suppliers / subcontractors have been assessed?
  • What % of these are compliant?
  • When were the suppliers last assessed?
  • Do any suppliers have significant issues to resolve?
  • Do we have a view on the critical suppliers within the supply chain?
  • What high severity issues have occurred since the previous update?

How board members can help strong assessment of supply chain cyber security.

The board should ensure they are aware of the constraints that the organisation has in maintaining cyber assurance of the supply chain and, where possible, take action to ease those constraints. For example, by investing in tools and resources required for continuous monitoring.


Published

Reviewed

Version

1.0