Study. uk . com
  1. Home
  2. All questions
  3. Question 475

CISM study material · question 475 of 1000

NIST splits supply chain vulnerabilities into external and internal. Which pairing is correct?

  1. External: unpatched systems. Internal: supplier interdependencies
  2. External: interdependencies among suppliers and their weak cyber hygiene. Internal: unpatched systems and poor cyber awareness
  3. External: regulatory change. Internal: supply disruption
  4. External: natural disasters. Internal: counterfeit components
Show the answer

Answer: B. External: interdependencies among suppliers and their weak cyber hygiene. Internal: unpatched systems and poor cyber awareness

SP 800-161r1 lists external vulnerabilities such as supply chain interdependencies, supplier weaknesses and inadequate cyber hygiene, and internal ones such as vulnerable systems and components, unpatched systems, ineffective controls and lack of cyber awareness.

Source: NIST SP 800-161 Rev. 1 (NIST) — Sec. 2.2 Cybersecurity Risks Throughout Supply Chains

Challenge yourself on this topic → Study as cards