Study. uk . com
  1. Home
  2. All questions
  3. Question 9

CISSP study material · question 9 of 500

A defence supplier is building a cyber supply chain risk management (C-SCRM) programme guided by NIST SP 800-161 Rev. 1, which applies C-SCRM at several organisational levels. Which artefacts does that guidance expect the programme to produce? Choose three.

  1. A C-SCRM policy setting direction for supply chain risk across the organisation
  2. A vendor questionnaire completed once at supplier onboarding and kept on file thereafter
  3. Risk assessments aimed at the particular products and services being acquired
  4. A strategy implementation plan that turns the C-SCRM strategy into scheduled work
Show the answer

Answer: D. A strategy implementation plan that turns the C-SCRM strategy into scheduled work
A. A C-SCRM policy setting direction for supply chain risk across the organisation
C. Risk assessments aimed at the particular products and services being acquired

The revision expects a strategy implementation plan, a C-SCRM policy, C-SCRM plans, and assessments of the specific products and services acquired; a one-off onboarding questionnaire replaces none of these.

Source: NIST SP 800-161 Rev. 1 (NIST) — SP 800-161 Rev. 1 > Abstract; Supersedes

Challenge yourself on this topic → Study as cards