Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 17 of 35

3. Manage your supply chain risk

It is almost inevitable that third-party goods (including open source components) and services will be incorporated into your product during its development. Whilst providing many benefits (such as cost and time savings), such inclusions can potentially introduce additional risks that need to be identified and managed.

Supply chain security should be in place to ensure third-party components are not compromised before they are incorporated into the build.

Examples of Defensive Measures

  • Adhere to the NCSC’s Supply Chain Security Principles.
  • Maintain an accurate inventory of all third-party goods, services and suppliers being used.
  • Identify who is responsible for the security of third-party supplied goods and services and ensure the controls in place are proportionate to the level of risk.
  • Establish how long third-party supplied goods (such as components or development tools) will be supported for, and whether this aligns with your product’s intended lifespan. Where there is misalignment, put appropriate mitigations in place (such as using an alternative).
  • Determine what the normal update cycle is (daily, weekly, etc.) for third-party supplied goods (such as components or development tools) and how these updates will be advertised and obtained.
  • Consider how often a third-party supplier checks for publicly known security vulnerabilities in their products and what actions they take if any are discovered.
  • Determine if the level of testing that has been performed on a third-party component by its original supplier is appropriate for its intended usage. If it is not, apply suitable mitigations (such as performing additional testing or using an alternative).
  • Apply updates as quickly as possible to original vendor-supplied, third-party components and development tools. This will help to reduce the likelihood of vulnerabilities.

Published

Reviewed

Version

1.0