- Home
- All questions
- Question 125
CISSP study material · question 125 of 500
A firm signs a supplier before any security review, intending to assess the supplier once the service is live. Which CSF 2.0 supply chain expectation does this breach most directly?
Show the answer
Answer: C. Planning and due diligence are performed before entering a formal supplier relationship.
CSF 2.0 requires planning and due diligence to reduce risk before a formal supplier relationship begins, not after the service is already running.
Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > Appendix A, GV.SC-04 and GV.SC-06