What does Secure by Design require when buying third-party technology?
Answered
Perform continual security due diligence on platforms, software and code. Mitigate risks and share findings with suppliers so they can improve. Pair with NCSC supply-chain expectations for AI components.
From the guidance
Primary (how) Secure by Design Principles
Where third-party products are used, perform security due diligence by continually assessing platforms, software and code for security vulnerabilities. Mitigate risks and share findings with suppliers to help them improve product security.
Section: 2. Source secure technology products
Related questions
- How should commercial teams apply Secure by Design when buying AI?
- Who is responsible for security when we use third-party AI components?
- Is Secure by Design mandatory for government AI services? Security and safe use of tools
- How do teams evidence Secure by Design? Delivery, assurance and operations
- When should we use third-party conformity assessment for AI? Delivery, assurance and operations