Managed Services and Security Assessment

Not surprisingly, most organizations also exist within some other organizations' supply chain. The principles of supply chain management must be applied to both upstream (supplier) and downstream (customer) relationships.

4 slides · 1 min read · Domain 8

Slide 1

Please take a moment and review the UK's National Cyber Security Centre (NCSC) Principles of Supply Chain Security, as an example.

As an example, the NCSC has proposed a set of 12 principles designed to help organizations establish effective control and oversight of their supply chain. These principles could be applied to any set of supply chain relationships but were developed in recognition of the risks of cyber-related compromises. Note that they apply equally to suppliers of both goods and services as well as to relationships with strategic partners.

The 12 Principles are

1. Understand what needs to be protected and why

2. Know who your suppliers are and build an understanding of what their security looks like

3. Understand the security risk posed by your supply chain

4. Communicate your view of security needs to your suppliers

5. Set and communicate minimum security requirements for your suppliers

6. Build security considerations into your contracting processes and require that your suppliers do the same

7. Meet your own security responsibilities as a supplier and consumer

8. Raise awareness of security within your supply chain

9. Provide support for security incidents

10. Build assurance activities into your approach to managing your supply chain

11. Encourage the continuous improvement of security within your supply chain; and

12. Build trust with suppliers

Several well-established standards address supply chain risk management. The ISO28000series of standards addresses the development and application of the supply chain security management system.

Reference: https://www.ncsc.gov.uk/collection/supply-chain-security/supply-chain-security-12-principles-infographic

Test this domain