- Home
- All questions
- Question 475
CISM study material · question 475 of 1000
NIST splits supply chain vulnerabilities into external and internal. Which pairing is correct?
Show the answer
Answer: B. External: interdependencies among suppliers and their weak cyber hygiene. Internal: unpatched systems and poor cyber awareness
SP 800-161r1 lists external vulnerabilities such as supply chain interdependencies, supplier weaknesses and inadequate cyber hygiene, and internal ones such as vulnerable systems and components, unpatched systems, ineffective controls and lack of cyber awareness.
Source: NIST SP 800-161 Rev. 1 (NIST) — Sec. 2.2 Cybersecurity Risks Throughout Supply Chains