Skip to main content
Guidance

Cyber Assessment Framework

The CAF is a collection of cyber security guidance for organisations that play a vital role in the day-to-day life of the UK, with a focus on essential functions.

Page 8 of 25

Principle A4 Supply Chain

iStock.com/elenabs

Appropriate organisational structures, policies, processes and procedures in place to understand, assess and systematically manage security risks to network and information systems supporting essential functions.




Supply Chain Security

Our guidance on supply chain security gives an overview of supply chain risks. It also provides references to further reading and guidance.

Secure Software Development and Support 

Your organisation needs to have confidence in the software it uses. Robust software development and support practices help organisations better manage the risks from poor software development practices and maintain trust in network and information systems supporting their essential functions.  

The NCSC Secure development and deployment guidance can help you improve and evaluate your development practices, and those of your suppliers. Similarly, the Software Security Code of Practice has been developed to improve the security and resilience of software that organisations and businesses rely on. 

Cloud service security

Where your organisation relies upon a cloud service, you should have confidence in the cyber security measures in place. Consider cloud-specific supply chain assurance guidance in NCSC cloud security principle 8: supply chain together with many cloud security assurance resources, including industry schemes such as the Cloud Security Alliance (CSA) Security, Trust & Assurance Registry (STAR) academic research and cloud provider information.

A4.a Supply Chain

You understand and effectively manage the risks associated with suppliers to the security of network and information systems supporting the operation of your essential function(s).

Not achievedPartially achievedAchieved
At least one of the following statements is true:All the following statements are true:All the following statements are true:

You do not know what data belonging to you is held by suppliers, or how it is managed. 

Elements of the supply chain for essential function(s) are subcontracted and you have little or no visibility of the sub-contractors.  

You have no understanding of which contracts are relevant and / or relevant contracts do not specify appropriate security obligations.  

Suppliers have access to systems that provide your essential function(s) that is unrestricted, not monitored or bypasses your own security controls.

You understand the general risks suppliers may pose to your essential function(s).  

You know the extent of your supply chain that supports your essential function(s), including sub-contractors. 

Suppliers to network and information systems that support your essential function(s) can demonstrate appropriate and proportionate levels of cyber security within the context of common threats. 

You understand which contracts are relevant and you include appropriate security obligations in relevant contracts.  

You are aware of all third-party connections and have assurance that they meet your organisation’s security requirements.  

Your approach to security incident management considers incidents that might arise in your supply chain.  

You have confidence that information shared with suppliers that is necessary for the operation of your essential function(s) is appropriately protected from common threats.

You have a deep understanding of your supply chain, including sub-contractors and the wider risks it faces.  

You consider factors such as your supplier’s ownership, nationality, partnerships, competitors, other organisations with which they sub-contract and their approach to cyber security. These factors inform your risk assessment and are fully considered in your procurement lifecycle processes and purchasing decisions. 

Your approach to supply chain risk management considers the risks to network and information systems supporting your essential function(s) arising from supply chain subversion by capable and well-resourced threat actors.   

Critical suppliers to network and information systems supporting your essential functions(s) can demonstrate appropriate and proportionate levels of cyber security within the context of capable and well-resourced threat actors.  

You have confidence that information held by suppliers that is essential to the operation of network and information systems supporting your essential function(s) is appropriately protected from capable and well-resourced threat actors.

You understand which contracts are relevant and you include appropriate security obligations, in relevant contracts.

You have a proactive approach to contract management which may include a contract management plan for relevant contracts.

Customer / supplier ownership of responsibilities is defined in contracts.

All network connections and data sharing with third parties are managed effectively and proportionately.

When appropriate, your incident management process and that of your suppliers provide mutual support in the resolution of incidents.

A4.b Secure Software Development and Support

You actively maximise the use of secure and supported software, whether developed internally or sourced externally, within network and information systems supporting the operation of your essential function(s).

Not achievedPartially achievedAchieved
At least one of the following statements is true:All the following statements are true:All the following statements are true:

Your software supplier(s) is unaware of the composition and provenance of software provided to you.

Software, including updates and patches, undergoes little to no testing.

Updates and patches often introduce new problems or fail to address existing issues.

Vulnerabilities are discovered in software despite the negligible difficulty of implementing mitigations.

Your software supplier leverages secure development principles and practices.

Your software supplier(s) can demonstrate a limited understanding of the composition and provenance of software provided to you.

You consider the security of environments (e.g. development, test and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of common threats.

The testing regime uses a range of different approaches (e.g. static and dynamic analysis, unit and integration testing and point in time assessments) that verify all aspects of the development lifecycle covering both functional and non-functional testing.

You have arrangements in place with your software supplier to receive timely security updates, patches and notifications.

Software, including updates and patches, is obtained from your supplier(s) via secure channels.

Your software supplier(s) has processes in place to identify, report and mitigate security vulnerabilities.

You have arrangements in place with your software supplier to be notified of any significant events that may adversely impact network and information systems supporting your essential function(s).

If open-source software is used, you have taken appropriate and proportionate steps to establish and maintain sufficient confidence in its security for its use.

You have appropriate support and maintenance arrangements in place.

Your software supplier(s) leverages an established secure software development framework (e.g. NIST Secure Software Development Framework (SSDF), Microsoft Secure Development Lifecycle (SDL)).

Your software supplier can demonstrate a thorough understanding of the composition and provenance of software provided to you, including any third-party components used in the development of that software, and those components are being monitored for new vulnerabilities throughout the lifespan of the product.

You consider the security of environments (e.g. development, test, and production), including source code and repositories, used in the production of software to be appropriate and proportionate within the context of capable and well-resourced threat actors.

The software development lifecycle is informed by a detailed and up to date understanding of threat and applies appropriate techniques, such as threat modelling, to identify and assess potential vulnerabilities and attack vectors.

You can attest to the authenticity and integrity of software, including updates and patches.


Published

Reviewed

Version

4.0