UL unveils vendor cybersecurity evaluation tool

May 26, 2020
New designation analyzes a vendor's security practices across multiple trust categories, resulting in a documented supplier "Trust Level rating"
Ul Mark 5ecd3056a5343

NORTHBROOK, Ill., - UL last week unveiled its Supplier Cyber Trust Level solution, which helps organizations minimize supply chain cybersecurity risk by focusing on the trustworthiness of suppliers' security practices.

According to a press release, the UL Supplier Cyber Trust Level analyzes a vendor's security practices across multiple trust categories, resulting in a documented supplier Trust Level rating. This rating demonstrates the trustworthiness of a supplier's security practices across the software and hardware development lifecycle, hosted systems, information management systems and their third-party management. 

"There is currently no single certification or framework on the market that adequately addresses the complexities of securing an enterprise wide supply chain," the release says. "Individual, separate security industry standards and certifications often address only a portion of the overall cybersecurity posture, which means they do not address other security aspects that are often critical for the supply chain. The UL Supplier Cyber Trust Level assessment enables a holistic view of supplier's security posture, while providing a fair and consistent evaluation for organizations of the cybersecurity posture from supplier to supplier."   

"A supplier's security-oriented culture, security processes and practices and secure R&D environments are all critical when validating supplier security," explains Isabelle Noblanc, global vice president and general manager of the Identity Management and Security division at UL.  

The UL Supplier Cyber Trust Level leverages security controls from many well-known industry best practices, standards and frameworks, including National Institute of Standards and Technology (NIST) cyber supply chain risk management, European Union Agency for Cybersecurity (ENISA) supply chain attacks, North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP)-013-1 standard, International Electrotechnical Commission (IEC) 20243-1, 62443-4-1 and 62443-2-4 standards and International Organization for Standardization (ISO) 27001 standard, among others. 

Helping suppliers to better understand gaps in their security posture, the UL Supplier Cyber Trust Level also helps them implement and strengthen continuous improvement plans and demonstrate and differentiate security strengths to multiple customers and groups of stakeholders. This comprehensive approach in working with both organizations and suppliers helps holistically strengthen the security of supply chains and the digital economy. 

The UL Supplier Cyber Trust Level joins a growing list of UL IoT security solutions, including the UL IoT Security Rating, services for IEC 62443 and UL 2900 Series of Standards, and security by design training, advisory and testing services, that address secure product development, cybersecurity in smart ecosystems and supply chain risk management. 

"The COVID-19 outbreak has made it clear how vulnerable supply chains can be. Although the COVID-19 situation has exposed vulnerability related to the availability of supply chains, it has also raised further awareness that cybersecurity is another prominent threat to supply chains worldwide. The UL Supplier Cyber Trust Level solution will help companies globally to better secure their supply chains and help bring safer products to the market," Noblanc said.