Study. uk . com
  1. Home
  2. All questions
  3. Question 484

CISM study material · question 484 of 1000

Which two acquisition practices does NIST name for managing supply chain risk? Choose two.

  1. Establishing a checklist of security requirements completed as part of procurement requests
  2. Restricting purchases to domestic suppliers
  3. Requiring every supplier to hold cyber insurance
  4. Obtaining open source software only from vetted and approved libraries
Show the answer

Answer: A. Establishing a checklist of security requirements completed as part of procurement requests
D. Obtaining open source software only from vetted and approved libraries

SP 800-161r1 names practices including a checklist of acquisition security requirements for procurement requests, due diligence on bidders, obtaining open source from vetted and approved libraries, an approved products list, and a prohibited supplier list.

Source: NIST SP 800-161 Rev. 1 (NIST) — Sec. 3.1.1 Acquisition in the C-SCRM Strategy

Challenge yourself on this topic → Study as cards