UNCLASSIFIED
5.5
Supply Chain Security
All organisations increasingly source ICT systems and software from a global
network of suppliers, distributors and business partners. The advantages of a
global ICT supply chain including competitive prices, innovative products and
flexibility. Regrettably, there is clear evidence that global ICT supply chains have
heightened system and software risks. Thus, supply chain security measures
aim to help achieve the mandated minimum-security outcomes below.
IS4 – All organisations must mitigate risks of intentional and unintentional
supply chain compromise. As a minimum requirement, organisations must: (a)
establish consistent supply chain security processes with clear lines of
accountability; (b) ensure that suppliers are subject to and pass a national
security impact assessment; (c) include security clauses in service contracts;
(d) ensure that the computer networks, products and services supplied do not
introduce information security risks; (e) assess compliance with requirements
at least annually; and, (f) enforce sanctions for non-compliance.
To achieve the security outcomes mandated above, organisations must:
Identify and evaluate the security risks related to outsourcing or offshoring
before letting contracts for critical infrastructure and services;
Recognise that they retain accountability for managing their information risks
even where they outsource ICT systems and services to third parties;
Ensure that they are fully acquainted and compliant with the national security
impact assessment process for ICT suppliers;
Abide by PPDA instructions to identify, document and incorporate security
requirements into outsourcing contracts with suppliers and contractors;
Require contractors to present an operational security management plan
outlining their strategy for reducing security risks to acceptable levels;
Outline the process for the development and maintenance of procedures,
processes, instructions and plans for securing the system;
Issue Security Aspects Letters (SAL) regularly to update contractors on the
security conditions that govern their access to critical infrastructure assets;
Require suppliers to obtain approval for physical facilities before the hosting
of GoU and other critical infrastructure systems and services; and
At least annually, obtain independent assurance that suppliers are complying
with the mandated NISF requirements and other security policies.
26