Study. uk . com
  1. Home
  2. All questions
  3. Question 126

CISSP study material · question 126 of 500

An incident response plan lists only internal teams. The organisation's payroll, identity and hosting all sit with third parties. Which CSF 2.0 supply chain outcome does the plan miss?

  1. Suppliers are prioritised by criticality before contracts are signed.
  2. Supply chain risk management is folded into enterprise risk management.
  3. Relevant suppliers and third parties are included in incident planning, response and recovery.
  4. Supplier requirements are integrated into contracts and agreements.
Show the answer

Answer: C. Relevant suppliers and third parties are included in incident planning, response and recovery.

CSF 2.0 expects relevant suppliers and other third parties to be included in incident planning, response and recovery activities rather than brought in once an incident starts.

Source: NIST CSWP 29 (NIST) — NIST CSWP 29 > Appendix A, GV.SC-08

Challenge yourself on this topic → Study as cards