Supply chain security
Supply chain security requires organizations to manage and mitigate risks stemming from their direct suppliers and service providers. It mandates a proactive approach to ensuring that third-party products, software, and services do not introduce vulnerabilities into the organization's own infrastructure.
What it means
The intent of this requirement is to address "indirect" security threats. Because modern organizations rely heavily on external vendors for cloud hosting, managed services, and specialized software, a vulnerability in a supplier’s environment can become a backdoor into your own.
In practice, the scope extends beyond simple procurement. It covers the entire lifecycle of the relationship: from initial due diligence and selection to ongoing monitoring and secure offboarding. You must treat critical suppliers as an extension of your own attack surface.
This also includes focusing on the quality and integrity of the products themselves. This means ensuring that hardware is authentic and software is free from known vulnerabilities or malicious injections before it is deployed in your environment.
How to meet it
- Establish a Third-Party Risk Management (TPRM) framework that defines how suppliers are categorized by criticality and risk level.
- Perform security due diligence on all high-risk vendors prior to onboarding using standardized questionnaires or independent audit reports.
- Incorporate mandatory security requirements into contracts, including breach notification timelines, right-to-audit clauses, and minimum security standards (e.g., ISO 27001).
- Maintain a comprehensive inventory of critical suppliers and the specific services or data they handle.
- Implement periodic reviews of vendor security posture, such as annual reassessments or reviewing updated SOC2 reports.
- Request Software Bill of Materials (SBOMs) for critical software to identify and manage vulnerabilities in open-source components used by your vendors.
Evidence an auditor asks for
- A register/inventory of third-party suppliers categorized by their risk level to the organization.
- Completed security assessment questionnaires or due diligence reports for key vendors.
- Signed contracts or Service Level Agreements (SLAs) containing specific cybersecurity obligations and liability clauses.
- Records of periodic vendor reviews, including evidence of follow-ups on identified gaps in a supplier's security.
Common pitfalls
- "Set and forget" onboarding: Conducting a security check only once at the start of a contract and failing to monitor the vendor over time.
- Overlooking Shadow IT: Failing to apply supply chain controls to SaaS tools purchased by individual departments outside of central procurement.
- Lack of enforcement: Having strong security clauses in contracts but lacking a process to verify that the vendor is actually adhering to them.