ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementHard

A critical software component for a widely used public-facing application is developed by a third-party vendor. A recent supply chain attack affecting a similar vendor caused a significant outage for another organization. The security team is now tasked with assessing the risk associated with this third-party component. Which of the following is the MOST effective approach to manage this supply chain risk?

  1. ARequiring the vendor to provide a Software Bill of Materials (SBOM) and conduct regular security audits of their development practices.
  2. BImplementing a robust internal vulnerability management program for the public-facing application.
  3. CDeveloping an internal, proprietary alternative to the third-party component to reduce reliance.
  4. DNegotiating a service level agreement (SLA) with the vendor that includes hefty penalties for security incidents.
Show answer & explanation

Correct answer: A. Requiring the vendor to provide a Software Bill of Materials (SBOM) and conduct regular security audits of their development practices.

To effectively manage supply chain risk, especially given a recent attack on a similar vendor, an organization needs visibility and assurance into the vendor's security posture and the components they provide. Requiring an SBOM provides transparency into the software's composition, and regular security audits of the vendor's development practices directly assess their security controls, proactively reducing the risk of vulnerabilities being introduced or exploited in the supply chain.

Why the other options are wrong

  • B. Internal vulnerability management is good but doesn't address the inherent risks from the third-party supply chain.
  • C. Developing an internal alternative is a form of risk avoidance, which can be effective but is typically a long-term, expensive, and not always feasible solution for immediate risk management.
  • D. An SLA with penalties addresses the financial impact after an incident but does not proactively reduce the likelihood of the incident itself.

Supply Chain Security

The process of securing the entire lifecycle of a product or service, from design to disposal, including all third-party components and services.

  • Involves managing risks associated with vendors, suppliers, and external partners.
  • Focuses on transparency, trust, and continuous monitoring.
  • Tools include SBOMs, vendor risk assessments, and contractual agreements.

Memory trick: Vendor Beware: Know your parts, audit their processes, build trust.

More Security and Risk Management questions