To prepare for Step C: Discover and Step D: Embed, Tasks such as securing resources, developing tools and writing information security policies that guide the process are required. This Step draws together characteristics of information risk in the supply chain – such as categories of information shared and their relative risk – to create balanced and proportionate information security arrangements.