Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A software development team needs to ensure that only specific versions of libraries and approved open-source components are used in their applications to prevent known vulnerabilities from being introduced. Which security concept is this related to?
- AData Loss Prevention (DLP)
- BSupply Chain Security
- CSecurity Information and Event Management (SIEM)
- DIncident Response
Show answer & explanationAnswer & explanation
Correct answer: B. Supply Chain Security
Supply Chain Security focuses on mitigating risks associated with the products, services, and components that an organization acquires from external vendors. In software development, this includes ensuring the integrity and security of third-party libraries and open-source components, precisely as described in the scenario.
Why the other options are wrong
- A. DLP prevents sensitive data from leaving the organization, unrelated to software components.
- C. SIEM collects and analyzes security logs, not focused on component integrity.
- D. Incident Response deals with reacting to security breaches, not preventing vulnerabilities in components.
Supply Chain Security
The process of identifying, assessing, and mitigating risks associated with the products, services, and components that an organization acquires from external vendors.
- Applies to software, hardware, and services.
- Aims to prevent vulnerabilities and malicious code from entering systems.
- Crucial for modern organizations relying on third-party components.
Memory trick: Supply Chain Security is like carefully inspecting every ingredient that goes into your product.