Study. uk . com
  1. Home
  2. All questions
  3. Question 481

CISM study material · question 481 of 1000

NIST identifies a critical first step in managing supply chain risk. What is it?

  1. Appointing a supply chain risk officer at board level, so that the accountability sits above every one of the functions that is involved
  2. Publishing the organisation's own security requirements externally, so that any prospective supplier is able to read all of them first
  3. Ensuring a current and accurate inventory of supplier relationships, contracts, and the products and services they provide
  4. Requiring every one of the suppliers to hold a recognised security certification before any contract at all may be signed with any of them in the first place
Show the answer

Answer: C. Ensuring a current and accurate inventory of supplier relationships, contracts, and the products and services they provide

SP 800-161r1 puts an accurate, current record of who the suppliers are, what contracts bind them and what they deliver ahead of everything else. Nothing can be managed that is not known.

Source: NIST SP 800-161 Rev. 1 (NIST) — Sec. 3.1.1 Acquisition in the C-SCRM Strategy

Challenge yourself on this topic → Study as cards