Skip to main content
Guidance

How to assess and gain confidence in your supply chain cyber security

Practical steps to help medium to large organisations gain assurance about the cyber security of their organisation's supply chain.

Pages

Page 18 of 29

Stage 4: Integrate the approach into existing supplier contracts

With a new approach in place, review your existing contracts either upon renewal, or sooner where critical suppliers are concerned.
  • Expected outputs from Stage 4.

    • A register recording all your suppliers.
    • ‘High priority’ suppliers are risk assessed against defined security controls
    • Suppliers with security shortfalls are identified, and a plan to improve their security is agreed.
    • Improved approach based on lessons learned from the activity.
    • Performance is being regularly measured against defined metrics, visible to board members.

Reviewed

Version

1.0