- Home
- All questions
- Question 9
CISSP study material · question 9 of 500
A defence supplier is building a cyber supply chain risk management (C-SCRM) programme guided by NIST SP 800-161 Rev. 1, which applies C-SCRM at several organisational levels. Which artefacts does that guidance expect the programme to produce? Choose three.
Show the answer
Answer: D. A strategy implementation plan that turns the C-SCRM strategy into scheduled work
A. A C-SCRM policy setting direction for supply chain risk across the organisation
C. Risk assessments aimed at the particular products and services being acquired
The revision expects a strategy implementation plan, a C-SCRM policy, C-SCRM plans, and assessments of the specific products and services acquired; a one-off onboarding questionnaire replaces none of these.
Source: NIST SP 800-161 Rev. 1 (NIST) — SP 800-161 Rev. 1 > Abstract; Supersedes