Protective Security Policy Framework (PSPF) Release 2026
Part Two: Risk (sections 5 to 8) – Protective Security Policy Framework (PSPF) Release 2026

Protective Security Policy Framework (PSPF) Release 2026 0039: 0039 Manage security risks from procurement

Requirement 0039 (Part Two: Risk, section 6.1 Third Party Risk Management; applies to All entities; dated 31 October 2024; retained from Release 2025): The entity is accountable for the management of security risks arising from procuring goods and services and ensures procurement and contract decisions do not expose the entity or the Australian Government to an unacceptable level of risk. Accountability for outsourced goods and services stays with the entity; where risks cannot be reduced to an acceptable level or quantified, alternative procurement is sought and the decision recorded. The CSO owns procurement security risk except cyber (the CISO).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Part Two: Risk (sections 5 to 8) – Protective Security Policy Framework (PSPF) Release 2026

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.