Supply chain
Understanding the cyber security risks from suppliers and other third parties.
Page 7 of 8
Additional guidance

We collated the following supply chain documents for those organisations requiring more detailed guidance. This includes documentation from the NCSC, the US government’s CISA (Cybersecurity and Infrastructure Security Agency) and the NPSA (National Protective Security Authority).
-
Cyber Assessment Framework (CAF)
The CAF is designed as a systematic approach to assessing your cyber risks. Section A4 specifically looks at how supply chain risks can be managed.
-
Cyber Essentials
Cyber Essentials certification provides a tangible, efficient way for organisations to gain assurance that their suppliers, or other third parties, have effectively implemented fundamental technical controls and that they are protected from the majority of untargeted, commodity attacks.
-
Cloud Service Providers
Where your organisation relies upon a cloud service as part of your supply chain, you should have confidence in the cyber security measures in place.
-
Cybersecurity & Infrastructure Security Agency (CISA)
The US Government Agency - CISA provides lots of useful information
on managing the supply chain risk. -
National Protective Security Authority (NPSA)
The NPSA is the UK national technical authority for physical and personnel protective security, Their protected procurement guidance looks at all aspects of protecting the supply chain. Including: