Skip to content
arrow_back
ISM-1452policyASD Information Security Manual (ISM)

Perform Supply Chain Risk Assessments for System Suppliers

Assess each supplier of operating systems, applications, IT and OT equipment, and services to understand how they affect your system's security risk.

record_voice_over

Plain language

When you buy software, hardware, or services from outside suppliers, those suppliers can introduce risks into your systems without you realising it. This control asks you to run a supply chain risk assessment, which simply means checking each supplier of operating systems (the core software a device runs on, like Windows), applications (everyday programs), IT equipment (computers and network gear), OT equipment (operational technology, meaning machinery and devices that control physical equipment), and services, and working out how that supplier changes your overall security risk. The goal is to know the risk before it becomes a problem, not after.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

A supply chain risk assessment is performed for suppliers of operating systems, applications, IT equipment, OT equipment and services to assess the impact to a system's security risk profile.
policyASD Information Security Manual (ISM)ISM-1452
priority_high

Why it matters

Engaging suppliers without assessing them can let a weak vendor become the entry point for a breach, so a hidden third-party flaw quietly raises your whole system's risk.

settings

Operational notes

Keep the supplier register and assessments current, and re-run an assessment whenever a supplier is added, changes ownership, suffers an incident, or takes on a more critical role.

build

Implementation tips

  • The person responsible for procurement should build a register listing every supplier of operating systems, applications, IT equipment, operational technology (OT) equipment, and services, so you have a complete picture of who can affect your systems.
  • The IT or security lead should create a short, repeatable assessment form that captures each supplier's security practices, where they are based, who they subcontract to, and how a failure on their end would affect your systems.
  • Before signing any new contract, the manager approving the purchase should require a completed supply chain risk assessment for that supplier and record the resulting risk rating (for example low, medium, or high).
  • For each supplier rated medium or high, the security lead should document the specific impact to the system's security risk profile, meaning exactly which systems and data are exposed and how badly, so the business can decide whether to proceed.
  • The business owner or board should set a schedule to re-run these assessments at least annually and whenever a supplier changes ownership, suffers a breach, or takes on a more critical role.
fact_check

Audit / evidence tips

  • Askthe supplier register and the completed risk assessmentsLook atcoverage across all five categories named in the control: operating systems, applications, IT equipment, OT equipment, and servicesGoodis a register where every active supplier in these categories has a dated assessment, not just a handful of big vendors
  • Askhow the organisation decides which suppliers get assessedLook atthe documented criteria or scopeGoodshows a clear rule (for example, all suppliers touching production systems or sensitive data) rather than an ad hoc, memory-based selection
  • Askto see how a supplier's impact on the system's security risk profile is recordedLook atan actual risk rating and a description of which systems and data are affectedGoodlinks each supplier to concrete consequences, not a generic statement that 'all suppliers are low risk'
  • Askwhen assessments were last reviewed and what triggers a re-assessmentLook atthe dates and any records of reassessment after a supplier change or incidentGoodshows assessments are current (within the last year) and were refreshed when something material changed
  • Askwho signs off on a supplier once the assessment is doneLook atevidence that an accountable manager reviewed and accepted the risk before the supplier was engagedGoodshows named approval tied to each assessment, especially for medium and high risk suppliers
link

Cross-framework mappings

How ISM-1452 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 5.19ISM-1452 requires organisations to perform supply chain risk assessments across suppliers of operating systems, applications, IT/OT equip...
sync_altPartially overlaps(2)expand_less
Annex A 5.22Annex A 5.22 requires the organisation to regularly monitor, review and evaluate supplier information security practices and service deli...
Annex A 8.30Annex A 8.30 requires directing, monitoring and reviewing outsourced system development, which inherently involves managing third-party d...
linkRelated(1)expand_less
Annex A 5.21ISM-1452 requires a supply chain risk assessment for suppliers of operating systems, applications, IT/OT equipment and services to determ...

E8

ControlNotesDetails
handshakeSupports(1)expand_less
E8-MF-ML1.5E8-MF-ML1.5 mandates MFA for third-party online services with sensitive data to prevent unauthorised access

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for procurement and outsourcing controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls