
Work happens everywhere. In your office, on remote sites, at home, even in cafes. IT security is more complicated than ever.
Your organisation may take cyber security and information security seriously. But what about the suppliers who manage your devices, support your systems or hold your data?
An IT supplier’s security incident can quickly become your business problem. A compromised support account, insecure software update or outage at a service provider can expose information or interrupt operations.
Security standards help you assess these risks. But certification, framework alignment and maturity assessments tell you different things. Knowing the difference helps you ask better questions before trusting a supplier with access to your business.
Three names appear regularly in supplier security discussions: ISO 27001, the Australian Cyber Security Centre’s Essential Eight, and the US National Institute of Standards and Technology’s Cybersecurity Framework (NIST CSF).
They address different aspects of security and can work together.

The table draws on the official ISO 27001 overview, Essential Eight maturity model and NIST CSF guidance.
A certificate is useful evidence, but its scope matters. Check that it covers the supplier’s actual services, systems and locations relevant to your organisation. ISO 27001 is perhaps the strongest certification in this area, but your supplier’s certification needs to be relevant not just to their overall InfoSec processes, but also those specific to the services they are supplying to you.
Likewise, Essential Eight maturity provides insight into technical defences, but does not cover every security risk. ASD notes that the model was not designed specifically for enterprise mobility or operational technology, where additional guidance may be needed.
Supply chain security also extends to your supplier’s suppliers. NIST CSF 2.0 gives this explicit attention: organisations should understand critical suppliers, set security requirements and involve relevant providers in incident response and recovery planning. Ask who else can access your information, how those providers are assessed, and what happens if something goes wrong. NIST’s supply chain guide provides a useful starting point.
Other standards help build a broader picture of supplier capability. ISO 9001 covers quality management; ISO/IEC 20000-1 covers service management; ISO 14001 addresses environmental management; and ISO 45001 addresses occupational health and safety. Each provides assurance in its own area, rather than substituting for information security credentials. ISO’s management standards explain these different scopes.
Telestar’s Quality & Security page outlines our credentials across these areas, including ISO/IEC 27001 certification and Essential Eight Maturity Level 3.
When reviewing your IT supply chain, start with the providers that have the greatest access to your data and systems. Ask for current evidence, check what it covers, and make security an ongoing conversation throughout the relationship.