Skip to content
arrow_back
search
ISM-0731 policy ASD Information Security Manual (ISM)

CISO Oversight of Cyber Supply Chain Risks

The CISO is responsible for managing risks in their organisation's cyber supply chain.

record_voice_over

Plain language

The Chief Information Security Officer (CISO) needs to keep an eye on any risks that come from working with other companies or suppliers in relation to cyber security. This is really important because if a supplier has poor security, it can lead to stolen data, financial losses, or reputational harm to your organisation.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO oversees cyber supply chain risk management activities for their organisation.
policy ASD Information Security Manual (ISM) ISM-0731
priority_high

Why it matters

Without CISO oversight of supply chain risk, supplier weaknesses may go unmanaged, leading to breaches, data theft, and reputational and financial harm.

settings

Operational notes

Have the CISO set a cadence for supplier risk reporting, approve risk acceptances, and ensure supply chain risk assessments are updated when vendors or services change.

Mapping detail

Mapping

Direction

Controls