UNCLASSIFIED 5.5 Supply Chain Security All organisations increasingly source ICT systems and software from a global network of suppliers, distributors and business partners. The advantages of a global ICT supply chain including competitive prices, innovative products and flexibility. Regrettably, there is clear evidence that global ICT supply chains have heightened system and software risks. Thus, supply chain security measures aim to help achieve the mandated minimum-security outcomes below. IS4 – All organisations must mitigate risks of intentional and unintentional supply chain compromise. As a minimum requirement, organisations must: (a) establish consistent supply chain security processes with clear lines of accountability; (b) ensure that suppliers are subject to and pass a national security impact assessment; (c) include security clauses in service contracts; (d) ensure that the computer networks, products and services supplied do not introduce information security risks; (e) assess compliance with requirements at least annually; and, (f) enforce sanctions for non-compliance. To achieve the security outcomes mandated above, organisations must:  Identify and evaluate the security risks related to outsourcing or offshoring before letting contracts for critical infrastructure and services;  Recognise that they retain accountability for managing their information risks even where they outsource ICT systems and services to third parties;  Ensure that they are fully acquainted and compliant with the national security impact assessment process for ICT suppliers;  Abide by PPDA instructions to identify, document and incorporate security requirements into outsourcing contracts with suppliers and contractors;  Require contractors to present an operational security management plan outlining their strategy for reducing security risks to acceptable levels;  Outline the process for the development and maintenance of procedures, processes, instructions and plans for securing the system;  Issue Security Aspects Letters (SAL) regularly to update contractors on the security conditions that govern their access to critical infrastructure assets;  Require suppliers to obtain approval for physical facilities before the hosting of GoU and other critical infrastructure systems and services; and  At least annually, obtain independent assurance that suppliers are complying with the mandated NISF requirements and other security policies. 26

Select target paragraph3