Study. uk . com
  1. Home
  2. All questions
  3. Question 125

CISSP study material · question 125 of 500

A firm signs a supplier before any security review, intending to assess the supplier once the service is live. Which CSF 2.0 supply chain expectation does this breach most directly?

  1. Suppliers are included in incident response and recovery planning.
  2. Cybersecurity roles for suppliers are communicated internally and externally.
  3. Planning and due diligence are performed before entering a formal supplier relationship.
  4. Supply chain practices are monitored across the product life cycle.
Show the answer

Answer: C. Planning and due diligence are performed before entering a formal supplier relationship.

CSF 2.0 requires planning and due diligence to reduce risk before a formal supplier relationship begins, not after the service is already running.

Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > Appendix A, GV.SC-04 and GV.SC-06

Challenge yourself on this topic → Study as cards