This framework helps the government to manage supplier risk.
PDF, 167KB, 11 pages
PDF, 244KB, 16 pages
MS Excel Spreadsheet, 116KB
MS Word Document, 32.5KB
This file may not be suitable for users of assistive technology. Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email email@example.com. Please tell us what format you need. It will help us if you say what assistive technology you use.
This supplier assurance framework applies to contracts at the ‘Official’ information security level. It should:
- enable the early identification of high risk projects
- provide a framework for the risk management of contracts that is consistent, light touch but effective, understood by both government stakeholders and suppliers and enable information sharing and accountability
- inform the assurance approach taken to high, medium and low-risk contracts
It can be adapted for use in the wider government community as it allows organisations to interpret and apply it according to their business needs. It is particularly relevant where information is shared through contracts or agreements.
Published: 1 November 2013
Updated: 25 February 2015
- Updated framework documents in line with Security Policy Framework, ISO27001: 2013 standard and the Cyber Essentials scheme.
- First published.