Perform Supply Chain Risk Assessments for System Suppliers
Assess each supplier of operating systems, applications, IT and OT equipment, and services to understand how they affect your system's security risk.
Plain language
When you buy software, hardware, or services from outside suppliers, those suppliers can introduce risks into your systems without you realising it. This control asks you to run a supply chain risk assessment, which simply means checking each supplier of operating systems (the core software a device runs on, like Windows), applications (everyday programs), IT equipment (computers and network gear), OT equipment (operational technology, meaning machinery and devices that control physical equipment), and services, and working out how that supplier changes your overall security risk. The goal is to know the risk before it becomes a problem, not after.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
A supply chain risk assessment is performed for suppliers of operating systems, applications, IT equipment, OT equipment and services to assess the impact to a system's security risk profile.
Why it matters
Engaging suppliers without assessing them can let a weak vendor become the entry point for a breach, so a hidden third-party flaw quietly raises your whole system's risk.
Operational notes
Keep the supplier register and assessments current, and re-run an assessment whenever a supplier is added, changes ownership, suffers an incident, or takes on a more critical role.
Implementation tips
- The person responsible for procurement should build a register listing every supplier of operating systems, applications, IT equipment, operational technology (OT) equipment, and services, so you have a complete picture of who can affect your systems.
- The IT or security lead should create a short, repeatable assessment form that captures each supplier's security practices, where they are based, who they subcontract to, and how a failure on their end would affect your systems.
- Before signing any new contract, the manager approving the purchase should require a completed supply chain risk assessment for that supplier and record the resulting risk rating (for example low, medium, or high).
- For each supplier rated medium or high, the security lead should document the specific impact to the system's security risk profile, meaning exactly which systems and data are exposed and how badly, so the business can decide whether to proceed.
- The business owner or board should set a schedule to re-run these assessments at least annually and whenever a supplier changes ownership, suffers a breach, or takes on a more critical role.
Audit / evidence tips
- Askthe supplier register and the completed risk assessmentsLook atcoverage across all five categories named in the control: operating systems, applications, IT equipment, OT equipment, and servicesGoodis a register where every active supplier in these categories has a dated assessment, not just a handful of big vendors
- Askhow the organisation decides which suppliers get assessedLook atthe documented criteria or scopeGoodshows a clear rule (for example, all suppliers touching production systems or sensitive data) rather than an ad hoc, memory-based selection
- Askto see how a supplier's impact on the system's security risk profile is recordedLook atan actual risk rating and a description of which systems and data are affectedGoodlinks each supplier to concrete consequences, not a generic statement that 'all suppliers are low risk'
- Askwhen assessments were last reviewed and what triggers a re-assessmentLook atthe dates and any records of reassessment after a supplier change or incidentGoodshows assessments are current (within the last year) and were refreshed when something material changed
- Askwho signs off on a supplier once the assessment is doneLook atevidence that an accountable manager reviewed and accepted the risk before the supplier was engagedGoodshows named approval tied to each assessment, especially for medium and high risk suppliers
Cross-framework mappings
How ISM-1452 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 5.19 | ISM-1452 requires organisations to perform supply chain risk assessments across suppliers of operating systems, applications, IT/OT equip... | |
sync_altPartially overlaps(2)expand_less | ||
| Annex A 5.22 | Annex A 5.22 requires the organisation to regularly monitor, review and evaluate supplier information security practices and service deli... | |
| Annex A 8.30 | Annex A 8.30 requires directing, monitoring and reviewing outsourced system development, which inherently involves managing third-party d... | |
linkRelated(1)expand_less | ||
| Annex A 5.21 | ISM-1452 requires a supply chain risk assessment for suppliers of operating systems, applications, IT/OT equipment and services to determ... | |
E8
| Control | Notes | Details |
|---|---|---|
handshakeSupports(1)expand_less | ||
| E8-MF-ML1.5 | E8-MF-ML1.5 mandates MFA for third-party online services with sensitive data to prevent unauthorised access | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Procurement and outsourcing
See all Guidelines for procurement and outsourcing controls, or browse the full ASD ISM library.