Articles

Suppliers and external services: risk that arrives with the contract

Supplier risk that arrives with the contract: what stays yours and how it is managed.

Reading: 5 minCybersecurity Governance

Article cover: Suppliers and external services: risk that arrives with the contract

Buying a service does not move the risk with it. NIST SP 800-53 Revision 5 draws the boundary in the discussion of SA-9: the organisation has no direct control over the implementation of the required controls or the assessment of control effectiveness, yet “the responsibility for managing risks from the use of external system services remains with authorizing officials” (lines 17883–17889). What changes is the shape of the work: requirements before the contract, due diligence before signature, oversight while it runs, evidence, and an exit agreed at the start.

What the contract changes and what it does not

A supplier brings capability and the risk that travels with it; the buyer keeps the accountability for using it. SP 800-161r1-upd1, the current edition of NIST’s cyber supply chain risk management (C-SCRM) guidance, states the governance consequence: “C-SCRM is an enterprise-wide activity that should be directed as such from a governance perspective, regardless of the specific enterprise structure” (line 616). CSF 2.0 states the same as an outcome, GV.SC-02: responsibilities for suppliers, customers and partners are established, communicated and coordinated “internally and externally” (line 832). Neither sentence delegates anything to the supplier.

The cycle: requirements, diligence, oversight, evidence, exit

one external relationship

  requirements  ->  due diligence  ->  oversight  ->  evidence  ->  exit
  SA-9 (a)          GV.SC-06           SA-9 (c)       SA-9 (b)      GV.SC-10
  GV.SC-05          SP 800-161r1-upd1  GV.SC-07       SR-3 (c)      SP 800-161r1-upd1
                    line 2419, SR-6    SR-6           SR-2          line 2432

  +----------------------------------------------------------------------------------+
  |  at every stage the accountability for the decision stays with the               |
  |  organisation that bought the service                                            |
  +----------------------------------------------------------------------------------+

The five stages are one cycle, and the framing is this sheet’s own reading, not a model the sources name: statements become assessment criteria, criteria become checks, checks become records, and the records decide whether the relationship continues.

Requirements you can state

SA-9(a) requires providers of external system services to “comply with organizational security and privacy requirements and employ the following controls” named by the organisation (line 17872); GV.SC-05 asks for requirements “integrated into contracts and other types of agreements” (line 844). The discussion supplies the instrument: service-level agreements “describe measurable outcomes, and identify remedies and response requirements for identified instances of noncompliance” (line 17896). A remediation timeline for a stated severity is a different decision.

Due diligence before the signature

GV.SC-06 puts planning and due diligence before the formal relationship (line 848). The assessment is part of the bid review: “The RFP review process should also include any procurement-specific supplier risk assessment”; the criteria “will be heavily informed by the defined C-SCRM requirements” (line 2419). SR-6 names both objects to assess — “suppliers or contractors and the system, system component, or system service they provide” (line 24088). On certificates the source is narrower: it recommends “confidence-building mechanisms, such as third-party assessment surveys, on-site visits, and formal certifications (e.g., ISO 27001, IEC 62443-4-1)” for critical suppliers (lines 2808–2810), and separately allows existing documentation to be reused where it “may provide evidence to support C-SCRM” (lines 1032–1033). A certificate is one input, not the assessment.

Oversight while it runs

SA-9(c) requires “processes, methods, and techniques to monitor control compliance by external service providers on an ongoing basis” (line 17879); GV.SC-07 covers the whole relationship, from recording the risk a supplier poses to monitoring it (line 851). SR-6 sets the frequency as an organisation-defined assignment and allows the review by “an independent third party” (line 24100). Oversight needs a list first: “a current and accurate inventory of the enterprise’s supplier relationships, contracts, and any products or services those suppliers provide” (line 2333), so that priority goes to “those critical suppliers of the most strategic or operational importance” (line 2340). CSF 2.0 records the pair as GV.SC-04 and ID.AM-04 (lines 838, 876).

Evidence you can obtain

SA-9(b) requires the organisation to “define and document organizational oversight and user roles and responsibilities with regard to external system services” (line 17876), because, as the discussion puts it, “Organizations document the basis for the trust relationships so that the relationships can be monitored” (line 17893). SR-3(c) fixes where the record lives — security and privacy plans, the supply chain risk management plan, or an organisation-defined document (lines 23807–23809) — and SR-2 requires it to exist (line 23715). SP 800-161r1-upd1 names it a “shared responsibility model” that “distributes responsibilities and accountabilities” across stakeholders (lines 1568–1570): the supplier sits inside the model, not outside the accountability.

The exit was part of the contract

GV.SC-10 carries the cycle past the relationship: plans “include provisions for activities that occur after the conclusion of a partnership or service agreement” (line 862). SP 800-161r1-upd1 names one mechanism plainly: contracts “should include provisions that provide grounds for termination in cases where there are changes to cybersecurity supply chain risk that cannot be adequately mitigated” (line 2432). SR-12 is the asset-side counterpart for disposal of data, documentation, tools and components after the relationship ends (line 24289).

Two things that look like a taxonomy and are not

No document here defines a supplier-tier model. SR-6 asks whether a supplier can “effectively assess subordinate second-tier and third-tier suppliers and contractors” (line 24099) — a capability under review, not a classification to apply. “A supplier three tiers down in the supply chain” is one of three illustrative risk scenarios (SP 800-161r1-upd1, line 492). SP 800-161r1-upd1’s three levels — enterprise, mission and business process, operational — are the buyer’s own, not supplier tiers. What the sources support is segmentation by criticality (line 2340) and GV.SC-04.

Level and prerequisites

L2 — operational: run the governance cycle for one external relationship, from the requirements clause to the agreed exit. It assumes the L1 vocabulary of risk treatment, in which a supplier arrangement is one way risk is shared, and the L1 accountability principle. Control selection is a technical-area subject.

Where to go next

Sibling sheets are unpublished drafts.

References

  • NIST — SP 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations (September 2020) — https://doi.org/10.6028/NIST.SP.800-53r5 — the SA-9 statement and its discussion (the responsibility remaining with authorising officials, the chain of trust, the documented basis for trust, the service-level agreement sentence) and the SR family statements SR-2, SR-3, SR-6, SR-11, SR-12.
  • NIST — SP 800-161r1-upd1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations, errata update of the May 2022 edition (“INCLUDES UPDATES AS OF 11-01-2024; SEE APPENDIX K”, 1 November 2024) — https://doi.org/10.6028/NIST.SP.800-161r1-upd1 — the governance sentence, the supplier inventory and the priority given to critical suppliers, the procurement-specific supplier risk assessment and its criteria, confidence-building mechanisms and certificates as one input, the termination clause, and the illustrative “three tiers” scenario. Edition history: the update is the May 2022 text with the errata applied; NIST withdrew the un-updated May 2022 edition (https://doi.org/10.6028/NIST.SP.800-161r1) on 1 November 2024 and names this update as its superseding publication. Both files were read in this batch; every line reference in this sheet is to the update, and the one errata change that touches a sentence quoted here — the added IEC 62443-4-1 in the certification sentence — is quoted above in its updated form.
  • NIST — The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 (26 February 2024) — https://doi.org/10.6028/NIST.CSWP.29 — the GV.SC category and its subcategories GV.SC-01 to GV.SC-10, and ID.AM-04.