Skip to content
arrow_back
search
ISM-1569 policy ASD Information Security Manual (ISM)

Establish Shared Responsibility Model for Supply Chain

Suppliers and customers must document and share security duties to understand who is responsible for what.

record_voice_over

Plain language

This control is all about making sure everyone knows who is in charge of what when it comes to security. By clearly setting out each party's responsibilities between suppliers and customers, you prevent confusion. If it's not done, things can fall through the cracks, leaving your sensitive information exposed and putting your business at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A shared responsibility model is created, documented and shared between suppliers and their customers in order to articulate the security responsibilities of each party.
policy ASD Information Security Manual (ISM) ISM-1569
priority_high

Why it matters

Without a clear shared responsibility model, accountability gaps can lead to security breaches and data loss across the supply chain.

settings

Operational notes

Regularly review and update supplier/customer responsibility boundaries to keep obligations clear as roles and services change.

Mapping detail

Mapping

Direction

Controls