Certified Cloud Security Professional (CCSP)Legal, Risk and ComplianceMedium

A global e-commerce company is expanding its cloud presence and using multiple third-party vendors for specialized services (e.g., payment processing, content delivery, analytics). To effectively manage the associated risks, the company is developing a comprehensive supply chain risk management program. Which of the following is a foundational step in establishing this program?

  1. APerforming a thorough inventory and classification of all third-party vendors and their services.
  2. BMandating that all vendors achieve ISO 27001 certification.
  3. CConducting annual penetration tests on all critical vendor applications.
  4. DImplementing a Security Information and Event Management (SIEM) system across all vendor environments.
Show answer & explanation

Correct answer: A. Performing a thorough inventory and classification of all third-party vendors and their services.

A foundational step in any supply chain risk management program is to first understand the supply chain itself. This involves identifying all third-party vendors, the services they provide, and classifying them based on the criticality and sensitivity of the data/processes they handle. Without this inventory, effective risk assessment and control implementation are impossible.

Why the other options are wrong

  • B. Mandating certification is a control requirement, not the initial step of identifying and understanding the vendor landscape.
  • C. Penetration testing is a security assessment control, not the initial step for identifying and categorizing vendors.
  • D. Implementing SIEM is a control, not a foundational step for understanding the entire supply chain.

Supply Chain Risk Management (SCRM)

Supply Chain Risk Management (SCRM) is the systematic process of identifying, assessing, and mitigating risks associated with an organization's supply chain, particularly those involving third-party vendors and cloud service providers.

  • Crucial for managing third-party dependencies.
  • Starts with understanding the vendor landscape.
  • Aims to protect data, systems, and operations from external threats.

Memory trick: Know your vendors before you trust their chains.

More Legal, Risk and Compliance questions