My Department manages third-party supply chain cybersecurity through its Information Security Management System (ISMS) framework, which includes certification to the globally recognised ISO/IEC 27001 security standard. This standard governs the assessment and treatment of supplier-related risks and requires a systematic approach to identifying, assessing, and mitigating risks associated with supply chain and vulnerability management.
All third-party services are subject to appropriate due diligence, contractual and security requirements, and ongoing oversight to ensure that cybersecurity risks are effectively identified and managed. These measures form part of the Department’s broader strategy to maintain a robust and resilient cybersecurity posture.