Site icon Auspreneur

ACSC asks IT buyers to check the integrity and authenticity

The Australian Cyber Security Centre has demanded buyers check on the ‘’integrity’’ and ‘’authenticity’’ of IT purchases. This decision came a month after US agencies bought and installed counterfeit networking gear. 

ASCS updated its information security manual (ISM) on Thursday and introduced three new controls, numbered ISM-1790, ISM-1791 and ISM-1792.ASCS asks the buyers of IT – “applications, ICT equipment and services” – to verify the integrity of the product. As part of the acceptance of products and services”, and then to maintain integrity.

Suppliers should be consulted on how best to confirm the integrity of their products and services

Meanwhile, ISM offers proper guidelines for users on how to check the IT equipment. Make sure it’s in compliance with the controls. It advises, ‘’applications may benefit from delivery via encrypted communication channels. While ICT equipment may benefit from tracking and tamper-evident packaging’’. 

“In doing so, such measures are only beneficial if they are assessed as part of the acceptance of products and services. In all cases, suppliers should be consulted on how best to confirm the integrity of their products and services.” The ISM adds that while integrity is essential, “also is ensuring … authenticity.”

Also, ISM states, “For example, a counterfeit product or service securely delivered is still a counterfeit product or service that may not operate as intended or pose a risk to the security of a system,” 

Organisations should seek to establish cyber security expectations with their suppliers

ACSC spokesperson said, “provide additional clarity to organisations to help them more easily exercise due diligence with their procurements of products.”

“Ultimately, effective cyber supply chain risk management is based upon trusted partnerships between suppliers, manufacturers, distributors, retailers and their customers,” the spokesperson said.

“Organisations should seek to establish cyber security expectations with their suppliers, including software vendors. These expectations should be clearly documented in contracts. Memorandum of understanding to ensure vendors are appropriately managing their own security posture, including their cyber supply chain risks.

Exit mobile version