Study. uk . com
  1. Home
  2. All questions
  3. Question 379

CISM study material · question 379 of 1000

Security expectations are communicated to suppliers verbally at kickoff meetings and recorded in no agreement. Which CSF 2.0 outcome does this fail?

  1. Suppliers are known and prioritised by criticality
  2. Requirements to address supply chain cybersecurity risks are integrated into contracts and other agreements
  3. Suppliers are included in incident planning, response and recovery so that they act alongside the organisation's own teams
  4. Supplier risks are monitored over the whole course of the relationship rather than assessed only at the point it is entered into
Show the answer

Answer: B. Requirements to address supply chain cybersecurity risks are integrated into contracts and other agreements

CSF 2.0's GV.SC-05 asks for supply chain cybersecurity requirements to be set, ranked, and written into the contracts and agreements themselves. A verbal briefing leaves nothing enforceable.

Source: NIST CSWP 29 (NIST) — Appendix A GV.SC-05

Challenge yourself on this topic → Study as cards