Study. uk . com
  1. Home
  2. All questions
  3. Question 247

CISM study material · question 247 of 1000

A supplier contract ends and the supplier retains administrative access and copies of organisational data for months afterwards. Which CSF 2.0 outcome addresses this?

  1. Roles and responsibilities for suppliers are coordinated externally, so that each party knows who to contact during the relationship
  2. Due diligence is performed before the relationship begins, so that the supplier's own controls are known from the very outset of it
  3. Supply chain risk plans include provisions for activities after the conclusion of a partnership or service agreement
  4. Suppliers are prioritised by criticality
Show the answer

Answer: C. Supply chain risk plans include provisions for activities after the conclusion of a partnership or service agreement

CSF 2.0 subcategory GV.SC-10 requires supply chain risk management plans to include provisions for activities occurring after the conclusion of a partnership or service agreement, covering matters such as access and data.

Source: NIST CSWP 29 (NIST) — Appendix A GV.SC-10

Challenge yourself on this topic → Study as cards