Study. uk . com
  1. Home
  2. All questions
  3. Question 485

CISM study material · question 485 of 1000

A project timeline allows no room for supplier security assessment before award. What does NIST say organisations should do?

  1. Waive the assessment wherever the timeline does not permit it, and then record that waiver against the project's own risk register
  2. Build sufficient time into acquisition and project activities so supply chain risk activities can actually be completed
  3. Delegate the assessment to the prime contractor
  4. Complete the assessment after award as a condition of the first payment, so that the project's delivery schedule is not delayed by it
Show the answer

Answer: B. Build sufficient time into acquisition and project activities so supply chain risk activities can actually be completed

SP 800-161r1 asks that acquisition and project schedules carry enough time for supply chain risk work to actually finish, rather than treating it as something the timeline can squeeze out.

Source: NIST SP 800-161 Rev. 1 (NIST) — Sec. 3.1.1 Acquisition in the C-SCRM Strategy

Challenge yourself on this topic → Study as cards