Supply chain cyber security risk management framework

Document type:
Framework
Version:
v1.0.0
Status:
CurrentNon-mandated
Effective:
June 2026–current
Security classification:
OFFICIAL-Public
Category:
Cyber security

Introduction

The Queensland Government Enterprise Architecture (QGEA) includes the Information and cyber security policy (IS18).

IS18 seeks to ensure the Queensland Government apply a consistent, risk-based approach to the implementation of information and cyber security.

Queensland Government entities that must implement IS18 are required to establish and operate an information security management system (ISMS) based on ISO 27001 Information technology - Security techniques - Information security management systems – Requirements.

Other public sector entities are encouraged to apply IS18 as recommended better practice.

The Information and cyber security policy states that risk management is an integral part of operating an ISMS, and it is a policy requirement for agencies to apply a systematic and repeatable approach to security risk management.

The QGEA Business capability reference model also requires consideration of supply chain management, in recognition that risks to government services are often generated within the ICT supply chain.

Objectives, scope and audience

The objective of the SCCRMF is to provide actionable guidance to assist in the identification, assessment, and management of risks to resilience and continuity of effective operations that may manifest from within the supply chain. The SCCRMF seeks to deliver the following benefits to public sector entities managing supply chain cyber security risks by:

  • providing a consistent structure for applying supply chain cyber risk management processes and principles—this framework is designed to be proportionate to the level of risk, the effectiveness of the control environment and the potential speed and impact of risks on each organisation’s business operations
  • guiding the establishment of better practice risk frameworks that are aligned to business needs and integrated into public sector entities’ systems and processes
  • creating the foundations to build workforce capability for supply chain cyber security risk management
  • fostering a supply chain cyber risk-aware culture.

The SCCRMF is designed to help Queensland public sector entities better manage their supply chain risks and support the implementation of IS18 across both information technology and operational technology environments.

The scope for the SCCRMF includes:

  • establishing risk and organisational context for information, communications and operational technology supply chain risk management
  • cyber security principles and their application to the supply chain risk management context
  • recommended processes for supply chain risk management
  • considerations for implementation.

The SCCRMF is intended to support a diversity of organisations and stakeholders. It is not a substitute for other portfolio, program and procurement governance expectations or guidelines and it should be used to strengthen existing arrangements and align to challenges associated with increasing dependency on supply chains in the delivery of government services..

Audience

This document is primarily intended for staff involved in procurement, business planning, ICT planning, cyber project and program management, and ICT architecture-related activities. Audiences may include:

  • agency heads and senior executives
  • Chief Technology Officers (CTO)
  • Chief Information Officers (CIOs)
  • Chief Information Security Officers (CISOs)
  • Chief Procurement Officers
  • Chief Finance Officers
  • risk practitioners and managers
  • business planners
  • strategic policy officers
  • legal counsel
  • procurement or contract managers
  • cyber and ICT managers
  • ICT architects (information, application, technology and solution)
  • owners of procured systems delivering goods or services that may not be part of an ICT team
  • non-technical staff.

Defining the supply chain

IS0 27036-1 Cybersecurity — Supplier relationships define the supply chain as:

a set of organisations with linked set of resources and processes, each of which acts as an acquirer, supplier, or both to form successive supplier relationships established upon placement of a purchase order, agreement, or other formal sourcing agreement.”

Multiple definitions for supply chain exist within Queensland Government, although they all address common themes. For example:

  • Business Queensland defines a supply chain as: “a network of individuals and companies involved in creating and delivering a product or service to a consumer.”
  • QGEA Business capability reference model defines supply chain management as: “Planning, scheduling and controlling a supply chain and the sequence of organisations and functions that make or assemble materials and products from supplier to consumer.
  • Queensland Procurement Policy identifies supply chain as: “a channel of goods distribution, which starts with the ‘supplier’ of raw materials or components, moves through an operational process to the distributor and retailer, and finally to the consumer.

This document uses the ISO 27036 -1 definition to help establish consistent terms for acquirer and supplier relationships.

Roles and responsibilities

All public sector entities have a responsibility for managing cyber security and supply chain risks to the delivery of services. In addition, Queensland Treasury, the Department of Housing and Public Works, and the Department of Customer Services, Open Data and Small and Family Business hold specific whole-of-government responsibilities.

Queensland Treasury maintains the Queensland Government’s guide to enterprise risk management: Queensland Treasury A Guide to Risk Management (2020). This document provides an overview of the key concepts for risk management and guidance on how the risk management process can be applied by any Queensland public sector entity.

The Department of Housing and Public Works maintains the Queensland Procurement Policy (QPP).

The QPP sets best practice requirements for managing all forms of procurement, including:

  • whole of government governance structures for information sharing, strategic input and collaboration for specific procurement categories, including ICT procurement
  • the need to define specific requirements in procurement
  • quality planning requirements for procurement risk management
  • applying a ‘local benefits approach’ to procurement
  • three rules in relation to managing cyber security risk:
    • all details or data associated with determining a procurement strategy must be captured and stored securely and include consideration of cyber security risks and management of personal
    • agencies must consider requirements for the management of cyber security risk including within the supply chain
    • agencies must include appropriate clauses in contracts to manage information and cyber security risks.

The Department of Customer Services, Open Data and Small and Family Business (CDSB) is responsible for transforming government services through cross agency leadership and securing operating environments and services.

This includes leading a whole of government approach to cyber security.

CDSB provides the:

  • Queensland Government Enterprise Architecture, which sets out information communications technology policy, frameworks, tools and guidance
  • Queensland Government Cyber Security function, which sets the whole of government cyber security policy and assurance within the QGEA.

Public sector executives are responsible for implementing QGEA policies, frameworks and guidelines and managing enterprise risk—including risk associated with the information, communications and operational technology supply chain. This includes implementing effective portfolio, program and governance cyber security management arrangements.

Document relationships

The Supply Chain Cyber Risk Management Framework (SCCRMF) aligns to a suite of mandatory policies and guiding documents relating to information security, enterprise risk management, procurement, and supply chain risk, including:

  • Financial Accountability Act 2009
  • Financial and Performance Management Standard 2019
  • Financial Accountability Handbook
  • Queensland Treasury Risk Management Guidelines.
  • Queensland Procurement Policy (QPP)
  • Foreign Ownership, Control or Influence Risk Assessment Guidance (Cwlth)
  • Queensland Government Cyber Security Strategy
  • QGEA
  • Information and Cyber Security Policy IS18
  • ACSC Cybersecurity Principles.

Standards, references and resources

The SCCRMF draws from and synthesises better practice from a range of authoritative sources.

Different organisations have different requirements, and some need to balance the requirements of IS18 with Federal Government obligations and expectations. While comprehensive standards exist (such as ISO27036 Cybersecurity – Supplier relationships), these can be difficult to implement for small to medium-size public sector entities. This SCCRMF therefore combines the clearest and most actionable recommendations and requirements from these source documents, along with guidance from the Australian Cyber Security Centre (ACSC). Any entities operating under the Security of Critical Infrastructure Act 2018 may have specific obligations that will also provide inputs into their supply chain risk management decisions and processes.

Executives and personnel in public sector entities establishing, maintaining or enhancing a supply chain risk management program are encouraged to develop a wider understanding and application of these additional standards and resources and their relative value in supporting the development of organisational maturity in supply chain risk management. These sources are listed in the table below.

SourceValue contribution
Australian Cyber Security Centre Cyber supply chain risk managementOutlines 5 themes for better practice supply chain risk management
Australian Information Security Manual (ISM)Lists a series of activities to help control supply chain risk in procurement and outsourcing of products and services and managing supplier relationships combining guidance for both information technology and operational technology
ISO 27036 (1-4) Cybersecurity — Supplier relationshipsComprehensive international standard for managing supply chain risk throughout the product lifecycle
ISO 27002 Information security, cybersecurity and privacy protection — Information security controlsList of cyber security risk controls which include lists of considerations for managing information security within the supply chain
ITSAP.10.070 Cyber supply chain: An approach to assessing risk (Canada)Illustrates a lifecycle for supply chain risk and three elements for assessing supply chain risk
NIST SP 800- 161 Cybersecurity Supply Chain Risk Management Practices for Systems and OrganizationsComprehensive guidance that includes a list of supply chain risk controls mapped to NIST control frameworks, supply chain scenario samples and comprehensive document templates
NIST Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick-Start GuideProvides concise, consumable and actionable guidance on the process for researching and verifying supplier or product risks before procurement.
NIST Cybersecurity FrameworkOutlines broad principles and functions for cyber security to which Australia's cyber security principles align
NISTIR 8276 Key Practices in Cyber Supply Chain Risk ManagementDetails valuable practices for uplifting supply chain risk management capability, drawn from industry consultations
NIST IR 7622 Notional Supply Chain Risk Management Practices for Federal Information SystemsProvides actionable summary of supply chain cyber security program management activities and introduces product 'integrators' to suppliers and acquirer stakeholders.
NIST SP 800-53, Revision 5, Security and Privacy Controls for Information Systems and OrganizationsIncludes cyber security control sets relevant to supply chain risk management (similar to the ISM and ISO 27002)
National Cyber Security Centre (UK) Supply chain security guidanceOutlines 12 principles to help organisations manage supply chain risks, including examples of what 'good' and 'bad' practices look like operationally

Supply chain standards, references and resources

Cyber threat context

Queensland’s uptake in the use of technology across its public sector significantly contributes to delivering substantial benefits to all Queenslanders.

The uptake in use and dependence on digital technologies, third-party vendors and services increases the risk of service disruption or sensitive information being stolen and compromised due to deliberate or unintentional cyber security incidents. The rapid integration of artificial intelligence technologies into supply chains only augments these scenarios, and some of the largest compromises of personal information have been in the public sector environment.

Malicious cyber threats are actively targeting public sector supply chains and have compromised several systems and accessed sensitive data across the ecosystem to:

  • obtain valuable personally identifiable information about customers and staff
  • gain a financial advantage
  • gain a detailed knowledge of critical infrastructure and sensitive systems to disrupt them at a time of a cyber adversary’s choosing
  • access customer information held by suppliers
  • apply social engineering to privileged access users to gain access that blend in with normal activity
  • obtain cutting edge technology, research and intellectual property.

As at July 2026, the ACSC had identified the following top four cyber threats to Australian ICT and OT environments:

  • A sophisticated nation state threat actor uses supplier access and privileges (both physical and/or logical) and gains access to critical infrastructure and sensitive systems without detection to embed a malicious malware that will remain dormant until such time that geopolitical events suit the threat actor to trigger disruption to services.
  • A criminal organisation gains access to sensitive customer, staff, and commercial-in-confidence data stored by a supplier that can be exploited for financial gain using ransomware, identity theft or identity fraud, or blackmail.
  • A service provider with access to sensitive data and/or critical operational systems and which operates with privileged access is controlled, owned or influenced by foreign interests and is compelled to act to meet cyber adversary objectives.
  • A threat actor gains access to corporate environments that have minimal access controls, and accessing sensitive operational system information (architectural diagrams, response plans, standard operating procedures, and access data) that are typically stored within information sharing platforms or portals.

The ACSC also warns that cyber adversaries are always evolving and changing tactics, techniques and procedures (TTPs). Public sector entities should monitor ACSC and Queensland Government Cyber Threat Intelligence for the most contemporary advice on cyber adversary TTPs.

Complexity of the information communications technology and operational technology supply chain

Queensland’s public sector supply chain is a large and complex domestic and international ecosystem ranging from a simple procurement of laptops by a small agency from a local supplier, through to multi-billion-dollar infrastructure projects involving one or more internationally based suppliers. These global suppliers may be providing complex information, application, operational and physical technology assets and capabilities that have a significant cyber component as a core element.

Some Queensland agencies have a small number of suppliers they leverage, while larger organisations have thousands of suppliers that they rely on for a vast range of services, products, and capabilities.

Each supplier presents their own unique challenges integrating into the public sector supply chain requirements:

  • small and medium enterprises (SMEs) may be unable to afford the cyber security uplift of their organisations to meet the basic cyber requirements
  • large global suppliers may decline to adopt the public sector contractual requirements and mandate that they will set their own expectations, and the customer can take it or leave it
  • there may be a lack of visibility of where and how data provided by a public sector entity is being accessed or used by a supplier, and for what purposes, and this may be compounded by shadow artificial intelligence in supplier systems
  • the supplier may have limited visibility over its own supply chain, compounded by a lack of monitoring capability to maintain real-time supply chain situational awareness for fourth- and fifth- party suppliers
  • there may be insufficient cyber assurance activities conducted by the supplier during the design, build, or operation phases of key systems, services, or capabilities
  • there may be a lack of visibility of the end-to-end supply chain ecosystem, including what organisations are involved, where they are located, and who owns them.

Operational technology (OT) also presents unique supply chain risks. There are particular challenges in the OT environment in identifying ‘Crown Jewels’ and dealing with legacy industrial control systems. These challenges may include:

  • limited depth in the supplier chain and a dependence on few suppliers of specialist plant and equipment
  • vendor access and safety considerations
  • extended systems and configuration lifecycles, leading to more critical change and investment decision points
  • increasing internet connectivity and vendor remote access requirements at the same time as an increase in targeting interest for cyber adversaries.

While the SCCRMF provides a common approach to supply chain cyber risk management, a one size fits all approach will not work due to the size, operating context, and complexities across a set of such diverse public sector entities. Agencies should therefore leverage the framework as a basis but also adopt a pragmatic risk-based approach that works best for their respective environments.

Applying cyber security principles to supply chain risk management

While the SCCRMF provides a better practice framework for supply chain risk management, it is not mandatory under the current IS18 policy.

Queensland public sector entities should begin integrating the following cyber security risk management principles into their cyber security and procurement lifecycle management arrangements.

These principles are directly aligned to the ACSC Cyber Security Principles provide organisations with guidance on protecting services from cyber threats. The ACSC Cyber Security Principles are modelled on the NIST Cybersecurity Framework 2.0.

The cyber security principles are grouped into six functions:

  • Govern (GOV): Develop and maintain a strong and resilient cyber security culture
  • Identify (IDE): Identify assets and associated security risks
  • Protect (PRO): Implement and maintain controls to manage security risks
  • Detect (DET): Detect and analyse cyber security events to identify cyber security incidents
  • Respond (RES): Respond to cyber security incidents
  • Recover (REC): Resume normal business operations following cyber security incidents.

Processes

There are specific processes for Queensland public sector entities to consider in implementing the supply chain cyber risk management principles.

These processes are high-level considerations to provide entities the agility to apply internal arrangements that reflect specific organisational contexts.

Supply chain cyber risk management processes and the cyber security principles

There are 16 supply chain cyber risk management processes mapped to the cyber security principles.

  • Govern (GOV):
    • Establish and integrate governance arrangements.
    • Assign roles and responsibilities.
    • Determine skills for effective management.
  • Identify (IDE):
    • Identify critical systems and subsystems.
    • Understand supply chain dependencies for critical operations.
    • Understand hardware and software components in supply chains.
  • Protect (PRO):
    • Define supplier access requirements.
    • Analyse risks.
    • Set expectations.
    • Determine security performance measures.
    • Select controls and configurations.
  • Detect (DET):
    • Establish assurance measures and non-compliance boundaries.
    • Monitor performance.
  • Respond (RES):
    • Monitor requirements for change.
    • Manage incidents.
  • Recover (REC):
    • Collaborate and exercise to respond and recover.

The application of these processes should be selected to match the:

  • commensurate with the criticality of the service
  • business capability
  • organisations business continuity requirements
  • its underlying ICT or OT systems
  • level of risk identified in the supply chain dependency between the acquirer and the supplier.

Consider a phased approach to implementation proportionate to organisational maturity. Each process is described below.

1. Establish and integrate governance arrangements

Queensland public sector entities should consider the following recommendations for establishing and integrating supply chain cyber security governance arrangements into existing portfolio governance and internal control structures:

  • ensure supply chain risk management objectives align to strategic goals and objectives for the organisation
  • ensure supply chain risks to the organisation’s service delivery mission are analysed, recorded and reported to the enterprise risk management committee
  • include supply chain risk management performance metrics in internal and external audit functions
  • develop an organisationally specific supply chain cyber security risk management plan.

2. Assign roles and responsibilities

As a relatively new lens to view sources of organisational risk, it is important to identify role functions that require an expansion or investment in new skillsets. Assigning roles and responsibilities for supply chain risk management may include:

  • designate executive responsibility for leading agency-wide supply chain risk management activities
  • ensure adequate resources are allocated to identified roles and responsibilities to enable effective implementation of supply chain risk management objectives
  • define management roles and responsibilities for managing risks in the supply chain, including business sponsors, cyber security and risk functions, the role of the supplier, and human resources, privacy, legal and procurement responsibilities
  • assign responsibility for developing supply chain risk management strategy and policy
  • include requirements for supply chain risk monitoring and incident response in select information and operational security management roles
  • ensure both legal counsel and procurement roles and responsibilities are defined and understood.

3. Determine skillsets for effective management

Following from the identification of roles and responsibilities that may require an update or review to deliver supply chain risk management functions, the skillsets for these roles should be examined and clearly articulated:

  • system owners may require additional training and awareness relating to multiple facets of supply chain risk management across the development, procurement, and operation of the information system
  • human resource teams may require uplift in ensuring background checks and personnel security policies are in place and procedures document are adhered to, including for support staff potentially based offshore
  • legal teams may need to establish specific guidance on contract management to ensure supply chain risks are addressed early in the procurement lifecycle
  • procurement teams may need to increase collaboration with ICT, OT and cyber security practitioners to understand, train and implement the establishment of new processes, such as response to cyber security questionnaires, monitoring contractual obligations and decommissioning acquisitions in breach of documented cyber security expectations
  • cyber security teams, including cyber threat intelligence teams that need to expand intelligence collection to understand events and incidents in deeper layers of the supply chain
  • governance, risk and assurance teams may need to adapt security programs and audit scope and schedules to accommodate deeper analysis of risk and risk control application as they relate to supply chain risks.

For more information on cyber security skills and capability uplift, review the Queensland Government cyber skills framework.

4. Identify critical services and processes

The identification of critical services and processes is a repeatable analysis that examines how faults, failures or compromise could impact the delivery of the business objectives.

This also applies to information or operational technology that supports multiple business capabilities, which can increase the criticality of the technology where failure of a service or process can affect multiple portfolio objectives.

  • define a criticality analysis process to suit the organisational context
  • ensure the appropriate subject matter expertise is engaged; this will likely require a systems expert and a business capability or service line expert
  • develop an understanding of the processes, interactions, intersections, connections and dependencies between systems
  • identify operating states, including minimum tolerable operating states sufficient to support business continuity and resilience plans and objectives
  • assess impact of failure to meet operating states
  • attribute relative value and priority to the more critical systems that are enabling the most important services
  • understand and document redundancy and resilience in critical systems
  • document outcomes.

5. Understand supply chain dependencies for critical operations

Identifying critical systems and subsystems to the delivery of business capabilities and the service delivery objectives they enable, organisations should gain a detailed understanding of how the supply chain contributes to the desirable operating state. Consider the following characteristics of organisations and their systems and subsystems sourced from within the supply chain:

  • features and functionality
  • operating states and the levels of access required to maintain them
  • cascading impacts and dependencies if disruptions or faults occur, or if operational tolerances are exceeded
  • operational risks associated with foreign ownership, control, or influence
  • prior security incidents or threat intelligence reports
  • evidenced segregation of duties and authorities for initiating, approving and executing a change, access rights, code or any security controls.

6. Understand hardware and software components in the supply chain

The first step in understanding risk is transparency. Gaining a greater awareness of the software code and hardware components within the supply chain is a complex task. However, greater awareness will yield greater opportunities to effectively manage risk.

This is relevant for suppliers that are part of the technology enabling critical systems, and may not have the levels of assurance usually associated with major international companies that already provide high levels of security assurance (for example, major suppliers already authorised under the United States FedRAMP program, or suppliers which present evidence of SOC2 certification).

Identify technologies that help building a better understanding of supply chain ‘materials’ that may generate additional risks, such as:

  • acquiring information about systems provenance (the chronology of the origin, ownership, development, location, and changes to a system)
  • cloud-based products or services and their security configurations
  • network or edge devices
  • security risk controls
  • policies and security settings
  • systems architecture and control boundaries
  • physical or logical separations
  • local and remote management functions.

Consider establishing a system component inventory for those systems identified as critical to the delivery of government services. A system component inventory might include:

  • hardware description: manufacturer and model, maintenance support status or physical locations
  • software build information: developer, supplier, security attestation, product license type, maintenance or support contract status or license expiration date.

Graphic representations of system boundaries, critical components, subsystems and third- and fourth-party providers can also provide useful illustrations of systems resilience, along with roles and responsibilities for risk ownership across the supply chain. This includes applying security processes to maintenance support—for example where the supplier replaces hardware or an OT device under maintenance support.

For example, for software-enabled products and services, entities should consider requesting a software bill of materials (SBOM) from suppliers where proportionate to system criticality, business impact and supply chain risk. Expectations for the provision, format, maintenance and update frequency of SBOM information should be defined early in procurement and contract arrangements, particularly for software or platforms supporting critical systems or essential services.

Depending on the product or service being supplied, it is possible the acquiring organisation may need to request information that is proprietary or sensitive to the supplier. Ensure suppliers are afforded sufficient opportunity to identify and appropriately protect that information.

7. Define supplier access requirements

Ensure the requirements for supplier access to systems, assets and facilities are clearly defined, negotiated, documented and formally agreed. Once in place, ensure supplier staff and contractors only have the access they need and have agreed to data, capability, functionality, infrastructure and facilities. Supplier access arrangements should be periodically reviewed based on risk and business need.

Ensure information shared with, used, acquired or created by the supplier is appropriate for operational and security objectives and is logged and tracked, particularly for regulated information such as personally identifiable information, security sensitive, commercially sensitive or intellectual property protected data.

Also ensure there is a clear understanding of whether a supplier has a clear need for physical, administrative or logical access to the acquirer’s system, facilities and network infrastructure in order to deliver the service and meet operational tolerances; and if so, understanding if that access can become an attack vector by being compromised and allowing threat actors to exploit that access.

For critical systems and significant systems risk assessed as requiring additional oversight, ensure resources and appropriate skillsets are applied to the active monitoring and management of the supplier’s access. Ensure the systems and the information they store and transmit have been assessed using the Queensland Government Information security classification framework (QGISCF) business impact levels, and for any information classified as PROTECTED, additional systems, personnel and access controls aligned to the Australian Government Protective Security Policy Framework (PSPF) are applied.

This may require additional effort to review policy and to train and educate internal and supplier personnel. It may also require resources allocated to records management of access activity, and potential audit of records to support investigations if the supplier risk profile increases or following a cyber incident.

8. Analyse risks

Existing enterprise risk management frameworks should be evolved and matured to accommodate supply chain cyber security risk analysis. Queensland Government public sector entities can apply ISO31000—Risk management—Guidelines as a baseline for enterprise risk frameworks.

At its foundational levels, ISO31000 provides limited guidance specific to cyber security or supply chain risk management. Additional inputs into the risk assessment process may include:

  • ISO27005—Information security, cybersecurity and privacy protection—Guidance on managing information security risks, which sets out specific applications of ISO31000 for managing information security risks
  • AS IEC 62443—Security for automation and control systems—Part 3.2: Security risk assessment for system design, which integrates systems architecture into the risk assessment workflow and helps illustrate specific OT considerations in the risk analysis
  • AS/NZS Handbook167 Security risk management, which includes guidance specific to security risks, including threat analysis of adversary capability and intent, asset criticality analysis, and vulnerability analysis to better inform the inputs into the risk analysis
  • ISO31050—Risk management—Guidelines for managing an emerging risk to enhance resilience, which supports the analysis of volatile, uncertain, complex and ambiguous conditions common to sophisticated cyber security risk events
  • ISO56006—Innovation management—Tools and methods for strategic intelligence management—Guidance, which helps integrate future focus, intelligence collection, and the analysis and exploitation of ‘insight’ to generate recommendations for use in strategic planning and decision-making.

When establishing context as part of an effective supply chain risk analysis process, it is important to understand the internal and external context of the service, business, capability or system. From this point you must identify risks by understanding the associated vulnerabilities and exposure using threat and criticality analysis. Once risks have been identified, analysing risks against cost effectiveness, risk exposure and business impact in essential for evaluation and treatment of identified risks. In applying the elements of an effective supply chain risk analysis process, consider:

  • combined use of the QGEA Business Capability Reference Model and Business Services Classification Framework and Queensland Government Service Delivery Statements to help establish the risk context
  • authoritative inputs into the threat analysis—include national security and Queensland Government cyber threat intelligence products to inform threat analysis for critical systems
  • recognition that it may be the service, system, asset, information, supplier, or third- or fourth-party supply chain dependency that could be the target for cyber-attack
  • alternative methods of analysis for identification of systems and subsystem criticality, such as:
    • layers of protection analysis (LOPA)
    • failure modes and effects analysis (FMEA) and failure mode, effects and criticality analysis (FMECA)
    • cause and effect analysis
    • fault tree analysis (FTA)
    • cause-consequence analysis
    • bow-tie analysis
    • or other methodologies well suited to problem definition (for more information on alternative methods of systems risk analysis, see ISO31010—Risk management—Risk assessment techniques).
  • limitations associated with setting probability and likelihood metrics based on historical information to inform risk levels when intelligent, thinking cyber adversaries are on the constant hunt for innovation
  • the inputs required from both the acquirer and the supplier to adequately inform the risk analysis, and the agreements and arrangements for exchanging that information at different stages of the procurement lifecycle.

In some cases, the application, market prevalence or nature of certain products, systems or services may present risks associated with foreign ownership, control or influence (FOCI).

Critical or high business impact products, system or services should be examined for any FOCI related risks.

Where a products, system or service requires analysis of FOCI risk as part of the risk identification process, public sector entities are encouraged to refer to the Foreign Ownership, Control or Influence Risk Assessment Guidance (and associated FOCI awareness guidelines) published by the Department of Home Affairs.

9. Set expectations

A collective understanding of risks between the acquirer and supplier will help to set expectation in the system design and procurement stages, and this early expectation will help manage supply chain risks that can otherwise emerge from opaque security settings.

A collaborative security-in-design approach, working with solution architects, will help incorporate defensive design criteria into business requirements or validate security configurations prior to contract entry. Have these expectations transparent and well established at the start of the procurement lifecycle.

If a supply chain cyber security risk management plan has been developed, make it available during the early stages of procurement to help set supplier or offerer expectations.

Once a baseline is established, prepare for suppliers to propose alternative security control options and/or tailored control configurations—and be prepared to assess risks associated with these alternatives and negotiate agreements prior to product selection.

Recognise that control expectations change over time as new cyber vulnerabilities are exploited and/or or new technologies to manage vulnerabilities are adopted. To accommodate this likelihood for change across the product lifecycle, establish periodic acquirer/supplier security engagement sessions. Identify and document other triggers for engagement throughout the product lifecycle. For more information on monitoring requirements for change, see subsection 11.14.

10. Determine security performance measures

The security performance of the supplier will have a direct correlation to the level of security protection for business capabilities and information assets in the acquiring organisation.

Inclusion of security performance measures in contractual agreements will assist in supply chain risk management. Consider the need for business requirements such as:

  • limiting privileges
  • isolation of connected elements
  • identification of specific countermeasures to known vulnerabilities
  • establishing agreed Recovery Time Objectives and incident notification timeframes
  • agreements on trigger notification and incident communication measures
  • provision of business continuity and disaster recovery plans
  • identification of failover, redundant or alternative systems and plans to activate them
  • patching policies and frequencies
  • confirmation of cryptographic protocols and algorithms
  • validation and testing of secure backup/archive capability
  • acceptable security certification and assurance levels — including third-party assurance
  • provision of architectural diagrams to demonstrate isolation elements (sandboxes, gateways, virtual machines, quarantines, security tokens and API Keys, firewalls, access controls, secrets configuration points etc)
  • sharable triggers for notifications, audit trails, log alerts and alarms and associated retention specifications
  • evidence of insurance policies
  • location of data storage
  • demonstrable transparency for artificial intelligence components
  • frequency of penetration testing and verification of outcomes
  • demonstration of alignment to widely accepted architectural principles—for example The Open Group Architecture Framework (TOGAF) or the Cloud Security Alliance Cloud Controls Matrix (CSA CCM)
  • measures to validate target security levels (SL-T) for operational technology, ASD Essential Eight maturity levels or other control maturity frameworks
  • copies of documented password policies
  • communication requirements for custom code extension/configuration change management.

Security performance measures should be clearly identified and achievable (and commercially reasonable). The list above is neither exhaustive, nor would all considerations be required for all suppliers in the supply chain. Rather, take a risk-based approach to the selection of items to include in establishing supplier security performance measures.

As more services move to cloud-based applications, platforms and infrastructure, acquirers should also implement a “cloud use policy” and ensure personnel are trained in the implementation of the policy. Resources required by both the acquirer and supplier to meet security performance and supply chain assurance measures should be commensurate with the criticality of the systems and the relative business impact if the product or service is disrupted, corrupted or exploited.

11 Select controls and configurations

Public sector entities should identify and select controls to manage risk in the supply chain. IS18 policy requirements include the requirement for departments and agencies to implement an ISMS in accordance with ISO27001—Information technology—Security techniques—Information security management systems—Requirements.

However, subject to future updates of IS18, this does not include a mandate for a specific cyber security risk control framework. Public sector entities may therefore choose to implement other control frameworks, such as:

  • ISO27002—Information security, cybersecurity and privacy protection—Information security controls
  • ISO27017 Information technology—Code of practice for information security controls based on ISO/IEC 27002 for cloud services
  • ISO27036-3 Cybersecurity—Supplier relationships—Guidelines for hardware, software, and services supply chain security (Annex A maps to ISO27002)
  • Australian Government’s Information Security Manual
  • ASD’s Essential Eight
  • Prudential Standard CPS234—Information Security
  • NIST SP 800-53r5 Security and Privacy Controls for Information Systems and Organizations
  • Centre for Internet Security (CIS) Critical Security Controls
  • Payment Card Industry Data Security Standard (PCI-DSS)
  • Cloud Security Alliance (CSA) Cloud Controls Matrix
  • MITRE ATT&CK Framework.

Whichever control framework is selected, ensure the selection is based on alignment between the supplier and acquirer security contexts. Select and negotiate with suppliers those controls that mitigate risk to the effective operation of the business capability and the delivery of government services. This may include minimum security baseline information security requirements based on risk tolerances for hardware, software and services.

Document the framework selected, as well as the suite of controls and their role in mitigating risk, and integrate that documentation into contractual agreements, Service Level Agreements, and any other formal documents outlining acquirer expectations for security protection.

These can be:

  • specific contract clauses
  • shared responsibility arrangements
  • system security plans (SSP)
  • master service requirements/Service Level Agreements
  • zone, conduit and risk assessment requirements (ZCR) cyber security requirements specifications (CRS) (for the OT context)
  • documented security exhibits
  • security schedule
  • security addendum
  • service level agreements
  • contract variations.

12. Establish assurance measures and non-compliance contract boundaries

Setting expectations and business requirements for security protection is valuable, however the effectiveness of these arrangements can be eroded if suppliers breach their obligations without penalisation or recourse.

Assurance is a key element in building confidence the service, product or system is trustworthy. It provides measures of confidence that cyber security functions, features, configurations, policies and architecture agreed by the supplier are being delivered. Establish assurance measures early in the procurement selection process, such as:

  • demonstration of certifiable cyber security frameworks (such as NIST CSF, SOC2, CISA, ISO27001, Essential 8 or other contextually or industry relevant standards)
  • SBOMs
  • provision of audit reviews
  • provision of post incident reviews
  • site visits
  • configuration architecture
  • penetration testing and/or external attack surface management.

Also consider and agree what actions will be taken if assurance that the agreed cyber security business requirements are not achieved. Ensure the list of response actions is informed by legal counsel, is clearly embedded into contracts and is in alignment with the Queensland Procurement Policy. Actions to address non-compliance with assurance obligations may include:

  • requesting and monitoring tolerable boundaries and the implementation of remediation plans
  • establishing formal dispute resolution arrangements
  • seeking legal advice
  • applying financial penalties (subject to contract obligations)
  • Release of assets, for example returning information held in systems
  • seeking compensation and/or recovering costs if the omission leads to damages
  • temporarily halting contracts (where operational impacts are not critical to delivery of services)
  • terminating contracts.

13. Monitor performance

If non-compliance mitigation measures were identified, agreed and documented at the start of the product lifecycle, the acquirer and supplier will have a baseline cyber security performance management system that can be used to ensure information security risks are actively managed on an ongoing basis.

Performance of the cyber security system agreed between the acquirer and supplier needs to be monitored and verified to ensure the product or service is operating as intended. Monitoring and verification arrangements should be agreed and included in the contract.

The following performance verification considerations may be applied and provide a basis for supplier or acquirer collaboration, engagement and assurance:

  • supplier support activities align with the acquirer’s information security objectives
  • transparency that security control requirements are met, maintained and changed according to agreed parameters
  • verification the supplier has security practices in place and staff are trained to achieve them
  • agreement on the approach to network, application and equipment testing
  • arrangements are agreed for code inspection, analysis and testing
  • periodic testing of supplier or acquirer assumptions on trust boundaries and control ownership as part of a contractual requirement
  • agreement to facilitate (or demonstrate facilitation of) penetration testing, malware scanning or other security logic validation processes
  • updates and ongoing demonstration of compliance with industry standards and/or certifications
  • testing and demonstration that agreed controls are in place and operating as expected.

In addition to performance monitoring, also consider the value of monitoring changes to connections and identities of key personnel you depend on for managing risks within the supply chain.

14. Monitor requirement for change

Multiple sources of change will impact the management of cyber security risk in the supply chain. Anticipate change throughout the product lifecycle and set conditions for managing change with suppliers.

Change to risk profiles or triggering a need for product or service reconfiguration may emerge from:

  • the rapid pace of technology change in the digital economy
  • artificial Intelligence enabled malicious code and/or security defences
  • cyber-attack techniques and zero-day vulnerabilities
  • new laws and regulations
  • changes from mergers, acquisitions or bankruptcy
  • industry actions following high profile incidents
  • new organisational policies
  • changes to key personnel and roles previously associated with risk management and procurement monitoring functions
  • changes in third- and fourth party suppliers enabling the delivery of the primary supplier product or service
  • changes to foreign ownership, control, influence over a supply chain product, component or subsystem.

The continued operation of a system and its capacity to meet baseline security expectations therefore requires continuous monitoring and change management processes. Changes should be documented to support ongoing provenance, operational confidence and a record of modifications and change configurations.

Ensure that roles and responsibilities for overseeing and negotiation for change in supplier security settings and configurations are allocated to the appropriate delegate personnel.

15. Manage incidents

Mature organisations that are effective in supply chain cyber security risk management include critical suppliers, products and assets in their contingency planning, business continuity planning, incident response, and post incident reviews.

Consider the integration of select critical suppliers into incident and continuity plans and establish collaboration mechanisms to have supplier and acquirer plans, actions and response activities aligned, tested and validated:

  • use the criticality assessment to identify and agree on tolerable outages and Return to Operations (RTO) timeframes
  • document the conditions and thresholds under which specific information will be exchanged—this will build confidence in the relationship and help avoid overburdening the supplier with information requests
  • agree on timeframes for communication of specific information during cyber security incidents—include new systems or product vulnerabilities and the expectations for exchange of relevant risk information
  • jointly walk through, review and update incident response playbooks
  • nominate specific personnel and validate communications systems, processes and protocols
  • establish an understanding of collective systems monitoring activities and jointly assess gaps and vulnerabilities and ‘blind spots’
  • negotiate protocols for media management and public communication, then exercise these with scenarios that include public, media and political demands for situational updates.

Note that under the Information security incident reporting standard mandatory reporting obligations, agencies must immediately report incidents affecting medium or high levels of business impact and/or incidents affecting multiple systems/agencies.

This is relevant to supply chain incident management both to inform incident reporting and response agreements with suppliers and where a public sector entity is supplying services downstream to other public sector entities ‘acquiring’ their service.

16. Collaborate and exercise to respond and recover

When security breaches occur, the incident response—and potentially crisis management—arrangements in an organisation will depend on effective communication of situational awareness between the supplier and acquirer, integration of response playbooks, and regular timely communication of actions and issues.

These functions are critical interdependencies between the supplier and acquirer, and their effectiveness can be strengthened through:

  • documented process diagrams and communications trees
  • scenario-based exercising
  • desk-top exercising
  • functional exercising
  • collaborative post-incident reviews
  • joint after-action planning
  • coordination of business continuity planning arrangements.

Integrating supply chain risk management into minimum procurement practices

Use the guidance in this framework to inform procurement lifecycle actions that can assist in meeting mandatory Accountable Officer obligations under the Queensland Procurement Policy (QPP) and the QGEA (including the Information and cyber security policy (IS18)).

Contact

For further information, contact the Cyber Security Unit at csu.ciso@qld.gov.au.

References

Legislation and regulations

Queensland Government documents