Skip to content
arrow_back
search
ISM-1785 policy ASD Information Security Manual (ISM)

Develop and Maintain Supplier Management Policy

Ensure a policy is in place for managing relationships with suppliers in a consistent manner.

record_voice_over

Plain language

This control is about having a clear policy on how your organisation manages its relationships with suppliers. Imagine running a business where each supplier does their own thing without clear guidelines from you – it can lead to misunderstandings, missed expectations, or even security risks if they're handling sensitive information. A good policy keeps everyone on the same page and ensures your organisation doesn't get caught off guard by supplier issues.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A supplier relationship management policy is developed, implemented and maintained.
policy ASD Information Security Manual (ISM) ISM-1785
priority_high

Why it matters

Without a supplier relationship management policy, third-party access and contract requirements may be inconsistent, increasing data leakage and service outage risk.

settings

Operational notes

Define supplier due diligence, contract security clauses, third-party access approvals and offboarding steps; review the policy regularly to reflect supplier and risk changes.

Mapping detail

Mapping

Direction

Controls