Supply Chain Security July 2026
CTAG Supply Chain Security Resources
Approach to Third Party (Supply Chain) Risks, their Identification and mitigation derived from UK Public Sector fieldwork.
The Integrated Supply Chain Security and Assurance Framework structures supply chain risk into several core pillars, moving from evidence-based threat profiling to legal procurement controls and maturity tracking.
1. Strategic Foundation and Threat Profiling The framework is built on an evidence-based approach that mandates analysing historical supplier data breaches and attacks to inform dynamic threat profiles. These threat profiles prioritise public internet-facing services, which carry the highest risk of compromise. It identifies Identity and Access Management (IAM) exposure, Shared Responsibility Mapping (SRM) across cloud and on-premises deployment, and broader geopolitical risks. The SRM is a key component as client organisations must fully understand where the supplier responsibility ends and their consumer responsibility starts. This is critical for good governance and data protection. Table 4 summarises these risks.
Approach to Supply Chain Mapping
Threat Profile Priority
Description & Focus Area
Public Internet-Facing Services
Identifies and profiles suppliers with services exposed to the public web, treating them as high-priority risk vectors.
Identity and Access Management (IAM) Exposure
Analyses the risks associated with service-to-service authentication and human administrative access within the supply chain.
Shared Responsibility Mapping
Distinguishes and clarifies risk ownership across different deployment scenarios, including on-premises, Software as a Service (SaaS), and cloud-native environments.
Geopolitical Risks
Factors broader political and economic stability contexts into the overall supplier risk scoring. This includes where data is processed & stored.
Key software service Threat profiles and Risks (Source: Author).
Centralised Supplier Repository / Information Asset Register
A dynamic, relational Central Supplier Catalogue serves as the primary resilience tool, accommodating both standardised data and free-text fields. The catalogue/register is the absolute core of any supply chain security programme of work. The real power of this approach, comes when the community / eco-systems share them. Within a Local Authority in the UK, there could be upwards of 750 systems and services. This is highly complex and generates a mountain or lake of data. Where Councils share he same supplier, knowing which other Councils share that supplier and having a detailed inventory of that suppliers’ components, and versions can really help during an incident, immediately alerting who would be affected by an exploit. This is key to the “Defend as One” Programme of work. [67] Table 5, provides an information asset template . This can be formatted as XML or other metadata to allow easy electronic sharing. The version number will ensure consistent mapping of any version changes I the structure. This template could become a standard for use within UK Local Government, this would facilitate information sharing and Cyber Incident Response. Th version number included to reflect this is the initial version 1.0 suggestion as of July 2026. There will need to be an accessible repository for the standard, such as the CTAG Guidance repository
Information Asset Register (IAR) Template (Version 1.0 July 2026)
Field Category
Field Name
Description
Framework Mandated
Date entry created
The date the Asset record was created.
Framework Mandated
Date entry updated / reviewed
The Asset Record must be reviewed at least annually.
Framework Mandated
Unique Supplier ID (Unique Key)
A unique identifier that programmatically links the information asset to the Central Supplier Catalogue.
Framework Mandated
Processing / Hosting Supplier
Explicitly identifies the third-party supplier that is responsible for processing, managing, or hosting the information asset.
Framework Mandated
Product / Service version number
This is the product / service version number (Patch level).
Framework Mandated
Suppler Assertion Verification
Indicates whether the asset has been verified using automated discovery tools to validate the supplier's claims. Or that a CAF or similar audit exists
Framework Mandated
Supplier Cyber Essentials / Plus – or ISO 27001 etc. status recorded and verified
Record and verify the asserted security certifications held by the supplier.
(Review annually during contract)
Framework Mandated
DPIA Status
Tracks whether a standardised Data Protection Impact Assessment (DPIA) has been completed for the asset, particularly regarding supply chain changes. Whilst only mandated for complex systems, this is a very robust way to assure personal data, being processed and stored.
Standard Best Practice
Asset ID / Reference Number
A unique internal alphanumeric identifier assigned to the specific asset.
Standard Best Practice
Asset Name & Description
A clear title and brief summary of what the information asset is and its business purpose (e.g., "Customer Payment Gateway").
Standard Best Practice
Information Asset Owner (IAO)
The internal role, department, or individual who is ultimately accountable for the asset's security and lifecycle. A named individual is best, by default it will be the service owner.
Standard Best Practice
Data Classification
The sensitivity level of the data contained in the asset (e.g., Public, OFFICIAL, Internal, Confidential, Restricted).
Standard Best Practice
Format and Location
Where and how the asset is stored (e.g., AWS Cloud, On-Premises Server, Physical Records).
Standard Best Practice
Business Criticality (CIA)
An assessment of the impact on the business if the asset's Confidentiality, Integrity, or Availability is compromised.
Standard Best Practice
Modelling harm
Understand the harm caused in the event of a data breach, to an individual, community or other group, includes, physical, financial, reputational. This can align with the UK Data Classification Guidelines.
Standard Best Practice
Retention Period & Disposal
The required legal or operational lifespan of the data and the approved method for secure disposal at the end of its lifecycle. Remember data isn’t gone until the last backup is deprecated.
Information Asset Register Template (Source: Author)
Suppliers must actively maintain standardised assertions [63] regarding their patching status, encryption protocols, compliance certificates, and product liability. To ensure transparency, suppliers are also required to have a formal Vulnerability Disclosure Policy (VDP) so the organization is alerted to critical bugs before exploitation.[65] There are a number of commercial tools available that do this.
Technical Architecture and Asset Management
Scalable, real-time assurance is achieved through an API-driven architecture where either the organisation pulls data from supplier endpoints, or suppliers push updates to a central API. The architecture also explores using blockchain for non-repudiation, utilizing immutable timestamps to prevent suppliers from backdating compliance evidence after an incident.
Furthermore, an Information Asset Register (IAR) must be programmatically linked to the supplier catalogue using a Unique Supplier ID. An integrated Assurance Toolkit leverages open-source automated discovery tools to verify local network assets against supplier claims, establishing a "ground truth".
Governance and Compliance Alignment Policy governance is driven by the LACES framework (Local Authority Cyber Eco-System). [66] Supplier risks—such as IAM exposure and service criticality—are formally tracked in a dedicated Supply Chain Risk Register. To avoid "compliance fatigue," the framework maps requirements to a targeted, risk-proportional subset of the NCSC Cyber Assessment Framework (CAF) and EU NIS/NIS2 regulations. [63]
Procurement and Legal Integration Security is embedded into the procurement lifecycle using model contract clauses, rigorous tender questionnaires, and structured dropdown answers to enable automated scoring. Crucially, the framework enforces Legally Binding Assertions (LBAs), which tie a supplier's security claims directly to contractual limits of liability and insurance recourse. [64]
Maturity Modelling and Implementation Organisations evaluate their supplier assurance capabilities on a 0-to-5 maturity scale, progressing from non-existent/reactive checks (0-1) up to full lifecycle automated assurance and predictive risk modelling (5). The framework concludes with a four-phase roadmap for operationalisation, spanning research, tooling development, governance drafting, and alignment with GDS/DCMS architecture standards.
References:
Integrating Machine Learning and Business Intelligence into Supply Chain Risk Management for a Comprehensive Cybersecurity Framework: A Systematic Literature Review - MDPI, https://www.mdpi.com/2227-7080/14/4/194
Third-Party Risk Management: Ensuring Vendor and Partner Compliance with Data Protection Laws - ResearchGate, https://www.researchgate.net/publication/395476764_Third-Party_Risk_Management_Ensuring_Vendor_and_Partner_Compliance_with_Data_Protection_Laws
Cyber Third-Party Risk Management: A Comparison of Non-Intrusive Risk Scoring Reports, https://www.researchgate.net/publication/351567274_Cyber_Third-Party_Risk_Management_A_Comparison_of_Non-Intrusive_Risk_Scoring_Reports
Cyber Third-Party Risk Management: A Comparison of Non-Intrusive Risk Scoring Reports - Scholars Archive, https://scholarsarchive.library.albany.edu/cgi/viewcontent.cgi?article=1002&context=ehc_fac_scholar
The development of supply chain management cybersecurity risks: What past incidents - Iowa State University, https://dr.lib.iastate.edu/bitstreams/bbbea3cc-d43d-4b13-ab44-51c2e7a78eb8/download
Deciphering the Supply Chain Chessboard: The Science of Decision-Making in Risk Management - CyberRisk Alliance, https://www.cyberriskalliance.com/blog/deciphering-the-supply-chain-chessboard-the-science-of-decision-making-in-risk-management
Supply chain cybersecurity & compliance - Star | Global, https://star.global/posts/supply-chain-cybersecurity-compliance/
NIST 800-161: Cybersecurity Supply Chain Risk Management Steps - ComplianceForge, https://complianceforge.com/compliance/nist-800-161-compliance
Third-Party Risk Statistics 2026: Vendor & Supply Chain Risk - DeepStrike, https://deepstrike.io/blog/third-party-risk-statistics
Supply Chain Risk Management: A Strategic Guide for Modern Resilience - Panorays, https://panorays.com/blog/supply-chain-risk-management-strategies/
Third-Party Risk Management in Cybersecurity Reference | Advanced Security Authority, https://advancedsecurityauthority.com/third-party-risk-management-reference/
What Is Third Party Risk Management? 2025 Complete Guide - Isora GRC, https://www.saltycloud.com/blog/third-party-risk-management/
TPRM Maturity Model for Third-Party Risk: Complete Guide [2026] | Isora GRC, https://www.saltycloud.com/blog/tprm-maturity-model/
Third-Party Risk Management Frameworks: The Guide - Mitratech, https://mitratech.com/resource-hub/blog/third-party-risk-management-frameworks/
Supply Chain Risk Management: Best Practices - Drata, https://drata.com/learn/tprm/supply-chain-best-practices
A Multicriteria Decision-Making Approach to Building Resilience Along the Indian Medical Equipment Supply Chain | Request PDF - ResearchGate, https://www.researchgate.net/publication/389302015_A_Multicriteria_Decision-Making_Approach_to_Building_Resilience_Along_the_Indian_Medical_Equipment_Supply_Chain
Key Practices in Cyber Supply Chain Risk Management: Observations from Industry - NIST Technical Series Publications, https://nvlpubs.nist.gov/nistpubs/ir/2021/NIST.IR.8276.pdf
The Anatomy of a Good Concept: A Systematic Review on Cyber Supply Chain Risk Management - MDPI, https://www.mdpi.com/2071-1050/18/3/1151
Conduct an Effective Supply Chain Cybersecurity Risk Assessment - Onspring Technologies, https://onspring.com/resources/blog/conduct-an-effective-supply-chain-cybersecurity-risk-assessment/
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties, https://arxiv.org/html/2406.10109v1
Defending Against Software Supply Chain Attacks - CISA, https://www.cisa.gov/sites/default/files/publications/defending_against_software_supply_chain_attacks_508.pdf
The Benefits of a Software Bill of Materials Program at Nuclear Facilities - INL Digital Library - Idaho National Laboratory, https://inldigitallibrary.inl.gov/sites/sti/sti/Sort_65326.pdf
Organisation-Level SCF Certifications | SCF CAP Guide, https://securecontrolsframework.com/scf-certified/organisation-level-scf-certifications
A Complete Guide to Third-Party Security Assessment - SPOG, https://blog.spog.ai/a-complete-guide-to-third-party-security-assessment/
(PDF) Information Security Risk Management Model for Big Data - ResearchGate, https://www.researchgate.net/publication/362562040_Information_Security_Risk_Management_Model_for_Big_Data
Modelling the conundrums to cyber-risks management in logistics firms for supply chain social sustainability - Emerald Publishing, https://www.emerald.com/jeim/article/37/6/1885/1227695/Modelling-the-conundrums-to-cyber-risks-management
A Supply Chain Game Theory Framework for Cybersecurity ..., https://supernet.isenberg.umass.edu/Articles/SupplyChain-Cybersecurity-Investments-Network-Vulnerability.pdf
Assured Cyber Supply Chain Provenance Using Permissioned Blockchain, https://iti.illinois.edu/credc/researchactivity/assured-cyber-supply-chain-provenance-using-permissioned-blockchain
Managing cyber risk in supply chains: A review and research agenda, https://researchportal.hw.ac.uk/files/25264894/SCMIJ_AAP.pdf
Cyber Risks: Systematic Literature Analysis - International Institute of Informatics and Cybernetics, https://www.iiisci.org/journal/PDV/sci/pdfs/SA153UQ24.pdf
Cyber Supply Chain Risk Management: From Threats to Treatment | Scilit, https://www.scilit.com/publications/e3d0699efee879e39d63eabe9a91a08a
The relationship between cybersecurity awareness, cybersecurity supply chain risk management and firm performance - Emerald Insight, https://www.emerald.com/scm/article/30/5/497/1265668/The-relationship-between-cybersecurity-awareness
CyberSecurity Readiness: A Model for SMEs based on the Socio-Technical Perspective, https://www.researchgate.net/publication/367645669_CyberSecurity_Readiness_A_Model_for_SMEs_based_on_the_Socio-Technical_Perspective
Full article: A combined Blockchain and sero-knowledge model for healthcare B2B and B2C data sharing - Taylor & Francis, https://www.tandfonline.com/doi/full/10.1080/25765299.2023.2188701
The MARISMA- CPS pattern - Essex Research Repository, https://repository.essex.ac.uk/33036/1/1-s2.0-S0166361522001129-main.pdf
Evaluation of the Feasibility of Utilising a Low-Cost UWB Radar for Hardware Implant & Counterfeit Device Detection - INFO - Oak Ridge National Laboratory, https://info.ornl.gov/sites/publications/Files/Pub182146.pdf
Proceedings of the Cyber Supply Chain Risk Management for Critical Systems (CySCRM '24) - Pacific Northwest National Laboratory, https://www.pnnl.gov/sites/default/files/media/file/Final%20CySCRM%20Proceedings.pdf
Cyber Supply Chain Risk Management in the Netherlands ..., https://essay.utwente.nl/fileshare/file/96796/weiss_MA_eemcs.pdf
DORA: Managing Third-Party Risk in the Supply Chain | Eraneos, https://www.eraneos.com/articles/the-digital-operational-resilience-act-dora-and-the-management-of-third-party-risks-in-the-supply-chain-part-3/
Key Strategies for Managing Third-Party Risk Under DORA - Omada, https://omadaidentity.com/resources/blog/strategies-third-party-risk-dora/
Digital Operational Resilience Act (DORA) - eiopa - European Union, https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en
Third-Party Risk Management under DORA | SAP LeanIX, https://www.leanix.net/en/wiki/trm/third-party-risk-management-under-dora
DORA Third-Party Risk Management Compliance | Prevalent - Mitratech, https://mitratech.com/resource-hub/rc-use-case/eu-digital-operational-resilience-act-compliance/
CMMC 2.0 Compliance Templates - ComplianceForge, https://complianceforge.com/compliance/cmmc-compliance-dfars-252-204-7021
BOMs Away! Inside the Minds of Stakeholders:A ... - Oscar Chaparro, https://ojcchar.github.io/files/27-icse24-sboms.pdf
How to choose mitigation measures for supply chain risks | Request PDF - ResearchGate, https://www.researchgate.net/publication/265557093_How_to_choose_mitigation_measures_for_supply_chain_risks
(PDF) Risk‑Based Counterparty Due Diligence Framework for the Crude Segment: Case Study of PT Pertamina (Persero) - ResearchGate, https://www.researchgate.net/publication/401940558_Risk-Based_Counterparty_Due_Diligence_Framework_for_the_Crude_Segment_Case_Study_of_PT_Pertamina_Persero
A Supply Chain Game Theory Framework for Cybersecurity Investments Under Network Vulnerability, https://supernet.isenberg.umass.edu/visuals/POMS-May%202016.pdf
Cybersecurity and Supply Chain Risk Management Are Not ... - RAND, https://www.rand.org/content/dam/rand/pubs/research_reports/RRA500/RRA532-1/RAND_RRA532-1.pdf
Multi-criteria risk classification to enhance complex supply networks performance - PMC, https://pmc.ncbi.nlm.nih.gov/articles/PMC8561686/
Risk assessment of maritime container shipping blockchain-integrated systems: An analysis of multi-event scenarios | Request PDF - ResearchGate, https://www.researchgate.net/publication/360935055_Risk_assessment_of_maritime_container_shipping_blockchain-integrated_systems_An_analysis_of_multi-event_scenarios
Blockchain based cyber supply chain provenance, https://ws.engr.illinois.edu/sitemanager/getfile.asp?id=3163
Third-Party Risk in 2026: The Hidden Cyber Threat - SureCloud, https://www.surecloud.com/blog-hub/third-party-risk-cybersecurity-2026
NCSC Supply Chain Risk https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies
MDB Fast time comms paper [xxxxx]
UK Energy Cyber attacks. [xxxxxxx]
Practise Based Research https://www.creativityandcognition.com/wp-content/uploads/2011/04/PBR-Guide-1.1-2006.pdf
NLAWARP https://www.nlawarp.net
NFCC WARP: https://nfcc.org.uk/our-services/ddat/
Socitm Supply Cain Risk: https://socitm.net/resource-hub/webinars/260513-gca-hardware-market-volatility/
Vulnerability Disclosure Policy: https://www.ncsc.gov.uk/information/vulnerability-disclosure-toolkit
Last updated
Was this helpful?