How to assign a cyber risk profile to new procurement requests

Cyber risk profiles will be constructed and assigned depending on your council’s individual cyber risk evaluation framework and subsequent risk appetite. Therefore it will vary and you should consider each of these sections within the context of your own council.


Risk Assessments

Risk assessments refer to evaluations, often supported by questionnaires, to determine potential risk posed by any individual procurement request.

The answers to a risk assessment will correspond to your council’s cyber risk evaluation framework, which can allow you to assign a predetermined risk profile. It is important to note that each procurement request will not fit perfectly into a risk profile. You will need to tailor the risk profile and subsequent minimum security controls depending upon what is  being procured or the activity being undertaken.

Example questions to potentially include in a cyber security questionnaire

It is important to note that these are example questions and that for a full set of questions to be developed, they would need to be tailored to your specific council, risk appetite and procurement(s).

Assigning a risk profile

Here is a sample risk profile framework that offers an understanding of higher and lower risk factors attributed to procurement requests, however it is again important to know that this is just a sample - and that the framework you should use is that which should be determined and constructed by your council’s specific needs and risk appetite.

Once you have worked through the questionnaire, you can assign a risk profile to the new procurement request. This risk profile will then be used to determine the appropriate recommended security controls. This is another area where it will be extremely important to continually consult NCSC guidance when making your assignments.

Assets, impact, supplier risks and contract scale as equal component parts to constructing a cyber risk appetite with arrow to a list of risk profiles and descriptions