Supply Chain Risk Management Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Supply Chain Risk Management flashcards as text
What is a 'trusted supplier' program in the context of federal ICT procurement?
Answer: A vetting process to identify and use vendors who meet security standards and have demonstrated trustworthiness
Trusted supplier programs establish criteria for vetting vendors' security practices, integrity, and supply chain controls before purchasing their products.
What supply chain attack vector was demonstrated by the SolarWinds Orion incident?
Answer: Malicious code injected into a legitimate software update distributed to thousands of customers
The SolarWinds attack inserted malicious code (SUNBURST) into legitimate software updates that were then distributed and trusted by customers.
What is the purpose of a vendor risk assessment in ICT supply chain risk management?
Answer: To evaluate a third-party vendor's security practices, financial stability, and ability to protect government data
Vendor risk assessments evaluate whether suppliers have adequate security controls, business continuity plans, and integrity measures to be trusted partners.
Which federal law prohibits the use of telecommunications equipment from specific companies deemed national security risks in federal systems?
Answer: National Defense Authorization Act (NDAA) Section 889
NDAA Section 889 prohibits federal agencies from procuring or using telecommunications equipment from companies like Huawei and ZTE due to national security concerns.
What does 'hardware integrity verification' involve in supply chain risk management?
Answer: Inspecting physical hardware for signs of tampering or counterfeit components before deployment
Hardware integrity verification checks for physical tampering, counterfeit components, and unauthorized modifications that could introduce security risks.
What is the role of acquisition/procurement policies in managing supply chain risks?
Answer: To establish security requirements that vendors must meet before their products or services can be purchased
Procurement policies embed security requirements into the buying process so that only vendors meeting security standards can be selected.