What does Secure by Design require when buying third-party technology?

Answered

Perform continual security due diligence on platforms, software and code. Mitigate risks and share findings with suppliers so they can improve. Pair with NCSC supply-chain expectations for AI components.

From the guidance

Primary (how) Secure by Design Principles

Where third-party products are used, perform security due diligence by continually assessing platforms, software and code for security vulnerabilities. Mitigate risks and share findings with suppliers to help them improve product security.

Section: 2. Source secure technology products

Read this in Secure by Design Principles (opens in new tab)

Related questions