Skip to main content

Critical Information Infrastructure Supply Chain Programme Paper

Page 42

Chapter 6: Cyber Contractual Handbook for CIIs The Cyber Contractual Handbook (the ‘Handbook’) is a centralised service for CIIOs to access a repository of sound contractual terms for enforcing cybersecurity standards in vendor agreements that assists CIIOs in managing vendor contracts across the vendor lifecycle. The Handbook delivers transparent, open information sharing and collaboration between CIIOs, reducing the information asymmetry between vendors and CIIOs to level the playing field during contract negotiations. Simultaneously the Handbook increases efficiency for vendors serving CIIOs as it simplifies the contracting process by standardising controls and consistency of cyber contractual clauses.

6.1.The challenge to overcome: information asymmetry and market power of vendors CIIOs vary in size and cybersecurity capabilities. For CIIOs which are more established and matured in their respective industries, they are more likely to be able to negotiate for more stringent contractual clauses for enforcing cybersecurity standards in their vendor agreements. For CIIOs which are smaller in market size and less matured, they may not have access to these sound contractual clauses or unable to influence vendors for addition of more stringent contractual clauses. Additionally, there is an uneven playing field between vendors and CIIOs during contracting. As prominent technology vendors or niche providers have more market power than their CIIO purchasers, CIIOs are unable to create leverage to enforce cybersecurity contractual clauses due to the lack of purchasing power and limited vendor alternatives. Vendors' information asymmetry when negotiating contracts can be reduced if there is a process to share best practice contractual clauses for cybersecurity standards among the CIIOs. CIIOs have an opportunity to use the information to influence and negotiate for improved cybersecurity standards of vendors collectively.

6.2.The approach: Holistic management of cyber supply chain risks through cybersecurity contractual terms The Handbook is a living document for two-way information exchange to take place between CSA, Sector Leads and CIIOs to share inputs on the clauses and consolidation of Sector Leads’ and CIIOs’ feedback and experiences. Information sharing and exchange can be facilitated through various channels, such as forums and consultation sessions with Sector Leads and CIIOs. From the information gathered, coupled with the insights from the CII Cyber Supply Chain Assessment Toolkit, CSA can form a holistic view of the approach CIIOs are taking to address cyber supply chain risks through contractual terms. This view can lead to insights into the varying capabilities of CII vendors and the challenges that CIIOs have in negotiating with CII vendors and enforcing cyber contractual terms.

Page | 42


Turn static files into dynamic content formats.

Create a flipbook
Critical Information Infrastructure Supply Chain Programme Paper by Cyber Security Agency of Singapore - Issuu