Chapter 5: Cyber Toolkit
Supply
Chain
Assessment
An initial step towards increased cyber supply chain resilience is to increase the depth and completeness of visibility of vendors in the CII cyber supply chain at the national level and standardise the process of cyber supply chain risk management for CIIOs. Reaching this outcome requires a shared toolkit that unites CSA, Sector Leads and CIIOs under a single framework for cyber risk management and collects the necessary data to achieve nth Tier visibility of vendors in the CII cyber supply chain.
5.1.The challenge to overcome: cyber supply chain risks are hidden amongst complexity As described in previous chapters, the CII supply chain is complex, interconnected and multifaceted. CIIOs have varying levels of visibility of the cyber supply chains that make up their CIIs and manage the associated vendor risks independently using different approaches. As such, there is low visibility of CII cyber supply chain risks at the national level. This limited visibility translates to a reduced situational awareness of national supply chain risks possibly leading to an ineffective response to a potential incident. Cyber supply chain risk correlates with decreased visibility of how procured technology by the CIIOs is developed, sourced, integrated and deployed. Managing this risk without visibility of the vendors that make up the supply chain is a case of working with “known-unknowns”. Compounding the visibility issue is that risks lie deeper in the supply chain, beyond Tier 1. There are varying levels of completeness of inventories of Tier 1 CII vendors and limited lineof-sight into the CII vendor landscape that is needed to know which vendor relationships to manage more closely. Without a clear picture of the Tier 1 vendor landscape, it is difficult to gain any further visibility beyond this point. At the same time, identification of the criticality of vendors and vendor risks are in silos. Varied and non-standardised practices are used to calculate and analyse exposure to cyber supply chain risks across sectors. This lack of uniformity makes it difficult to consistently measure and understand risks across different CIIs, CIIOs and sectors. Additionally, this variation in approach across CIIOs and sectors extends to assessing and rating vendor cybersecurity capabilities. It is essential to understand the processes, procedures, and practices that vendors have in place to manage the cybersecurity and resilience of their organisation and the quality and integrity of the products and services they provide. Without a consistent approach to assessing and measuring vendor cybersecurity capabilities, it is challenging to standardise requirements on CII vendors to manage identified risks or develop the appropriate mitigating controls for CIIOs.
Page | 36