All organisations should consider cyber supply chain risk management. If another organisation is involved in the delivery of a product or service to your organisation, there will be a cyber supply chain risk originating from that organisation. Likewise, your organisation will transfer any cyber supply chain risk you hold to your customers.
Effective cyber supply chain risk management ensures, as much as possible, the secure supply of products and services for systems throughout their lifetime. For products, this includes their design, manufacture, delivery, maintenance and disposal. As such, cyber supply chain risk management forms a significant component of any organisation’s overall cyber security strategy.
Managing the cyber supply chain
Cyber supply chain risk management can be undertaken by identifying the cyber supply chain, understanding cyber supply chain risk, setting cyber security expectations with suppliers, auditing suppliers for compliance, and continual monitoring and improvement of cyber supply chain security practices.
Identify the cyber supply chain
The first step in cyber supply chain risk management is to identify the cyber supply chain. This includes all suppliers, such as software and hardware vendors, managed services providers, and where possible, their sub-contractors. Furthermore, it is important to know the value of information that your systems process, store and communicate, as well as the value of any information that may be entrusted to suppliers.
As a starting point, organisations should establish a list of suppliers they have business arrangements with. While an exhaustive list of all suppliers, especially their sub-contractors, may not be possible, the identification of those responsible for products or services with security enforcing functions, privileged access or handling particularly sensitive information should be prioritised.
Understand cyber supply chain risk
Following the establishment of a list of suppliers, organisations should seek to understand the cyber supply chain risk that those suppliers pose through established risk management practices within their organisation. In some cases, cyber supply chain risk relating to suppliers may be a result of poor security practices within a supplier, security vulnerabilities within a supplier’s product or service offerings, or due to a supplier’s exposure to extrajudicial control, extrajudicial influence or foreign interference.
In determining the cyber supply chain risk that suppliers pose, organisations can seek to understand the security posture of their suppliers in a number of ways. This may involve speaking to suppliers about their existing cyber security arrangements, determining whether suppliers hold any security certifications, looking at the track record of security vulnerabilities in a supplier’s product or service offerings and their responsiveness to resolving them, and whether the supplier has a vulnerability disclosure policy.
While the determination of cyber supply chain risk will often be the responsibility of individual organisations, in some cases the Government may deem a particular supplier, or one of their products or services, to be a national security concern. In such cases, there may be a specific direction issued in relation to managing the associated cyber supply chain risk. In particular, for critical infrastructure providers, the Security of Critical Infrastructure Act 2018  grants provision for specific direction to be issued by the Government where national security concerns exist.
As a result of understanding their cyber supply chain risk, organisations should be able to develop both a prioritised list of suppliers that present a high risk to their organisation along with an associated cyber supply chain risk management plan. It is important to note though that organisations should not only consider the cyber supply chain risk posed by their suppliers but also the cyber supply chain risk that they pose to their customers.
Set cyber security expectations with suppliers
Regardless of which suppliers are deemed a high risk at any given time, organisations should seek to establish cyber security expectations with all of their suppliers. As part of this, cyber security expectations should be clearly documented in contracts or memorandum of understandings in order to ensure that suppliers are appropriately managing their own security posture, including their cyber supply chain risk. Furthermore, it is critical that such agreements stipulate the requirement for any cyber security incidents to be openly and transparently reported to their customers and appropriate authorities in a timely manner.
In many cases, cyber security expectations set out in contracts or memorandum of understandings should not be excessively restrictive; except where suppliers are involved in the provision or support to highly classified systems. Rather, cyber security expectations should be justifiable, achievable and proportional to the information being entrusted to suppliers or the role that their products or services play in an organisation’s systems. For example, organisations may seek their suppliers to demonstrate good faith efforts to implement the Australian Cyber Security Centre (ACSC)’s Cyber Security Principles  and/or the Essential Eight Maturity Model .
Finally, organisations should seek to ensure that any cyber security expectations set out in contracts or memorandum of understandings with suppliers are passed through in turn to their suppliers.
Audit suppliers for compliance
Once cyber security expectations have been established with suppliers, it is important that organisations have confidence that those expectations are being met. One way to achieve such assurances is through routine audits or other forms of technical assessments. Provisions for such activities should be stipulated within contracts or memorandum of understandings (often referred to as a ‘right to audit’ clause) and can serve as a way to gain independent assurances of the security posture of suppliers.
Monitor and improve cyber supply chain security
Ultimately, effective cyber supply chain risk management is based upon trusting partnerships between suppliers and customers. Such partnerships can be strengthened through common cyber security goals and information sharing arrangements, such as sharing best practices and threat intelligence, as well as assisting each other with responding to cyber security incidents and involving each other in any cyber security exercises.
The Australian Government Information Security Manual (ISM) assists in the protection of information that is processed, stored or communicated by organisations’ systems. The Guidelines for Outsourcing in particular contain additional guidance on the procurement of outsourced services. It can be found at https://www.cyber.gov.au/acsc/view-all-content/ism.
The Strategies to Mitigate Cyber Security Incidents complements the advice in the ISM. The complete list of strategies can be found at https://www.cyber.gov.au/acsc/view-all-content/publications/strategies-mitigate-cyber-security-incidents.
Additional guidance related to cyber supply chain risk management can be found in the following ACSC publications:
- the Cyber Supply Chain Risk Management Practitioner Guide publication at https://www.cyber.gov.au/acsc/view-all-content/publications/cyber-supply-chain-risk-management-practitioner-guide
- the Questions to ask Managed Service Providers publication at https://www.cyber.gov.au/acsc/view-all-content/publications/questions-ask-managed-service-providers
- the How to Manage Your Security When Engaging a Managed Service Provider publication at https://www.cyber.gov.au/acsc/view-all-content/publications/how-manage-your-security-when-engaging-managed-service-provider
- the Cloud Computing Security Considerations publication at https://www.cyber.gov.au/acsc/view-all-content/publications/cloud-computing-security-considerations
- the Cloud Computing Security for Tenants publication at https://www.cyber.gov.au/acsc/view-all-content/publications/cloud-computing-security-tenants.
Additional guidance related to cyber supply chain risk management can be obtained from the following sources:
- the Attorney-General’s Department’s Security governance for contracted goods and services providers policy at https://www.protectivesecurity.gov.au/governance/security-governance-for-contracted-service-providers/Pages/default.aspx
- the Critical Infrastructure Centre’s Protecting your critical infrastructure asset from foreign involvement risk publication at https://cicentre.gov.au/resources
- the National Cyber Security Centre’s Supply chain security guidance at https://www.ncsc.gov.uk/collection/supply-chain-security
- the National Institute of Science and Technology’s cyber supply chain risk management project website at https://csrc.nist.gov/projects/supply-chain-risk-management/
- a collection of industry best practices for cyber supply chain risk management at https://csrc.nist.gov/Projects/cyber-supply-chain-risk-management/Best-Practices.
If you have any questions regarding this guidance you can contact us via 1300 CYBER1 (1300 292 371) or https://www.cyber.gov.au/acsc/contact.