Guidance
How to assess and gain confidence in your supply chain cyber security
Practical steps to help medium to large organisations gain assurance about the cyber security of their organisation's supply chain.
Pages
Page 18 of 29
Stage 4: Integrate the approach into existing supplier contracts
With a new approach in place, review your existing contracts either upon renewal, or sooner where critical suppliers are concerned.
Expected outputs from Stage 4.
- A register recording all your suppliers.
- ‘High priority’ suppliers are risk assessed against defined security controls
- Suppliers with security shortfalls are identified, and a plan to improve their security is agreed.
- Improved approach based on lessons learned from the activity.
- Performance is being regularly measured against defined metrics, visible to board members.