Supply Chain Risk Management Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Supply Chain Risk Management flashcards as text
What is a 'developer security' requirement in the context of supply chain risk management?
Answer: Requiring software developers and vendors to follow secure coding practices, conduct code reviews, and provide security testing evidence
Developer security requirements ensure that vendors build security into their products from the start through secure development lifecycle practices.
What federal acquisition regulation clause requires contractors to report cyber incidents affecting federal information?
Answer: DFARS 252.204-7012 (for DoD contracts)
DFARS 252.204-7012 requires DoD contractors to implement NIST SP 800-171 controls and report cyber incidents affecting covered defense information within 72 hours.
What is the purpose of a 'criticality analysis' in supply chain risk management?
Answer: To identify which system components, suppliers, and supply chain elements are most critical to mission success and require the most protection
Criticality analysis prioritizes supply chain protection efforts by identifying which components, if compromised, would have the greatest mission impact.
What supply chain risk does 'open source software' present that proprietary software does not?
Answer: Anyone can introduce malicious code via pull requests or dependency confusion attacks targeting public package repositories
Open source supply chain attacks exploit the ability to inject malicious code into widely used libraries or impersonate legitimate packages in public repositories.
How should organizations manage the risk of 'end-of-life' (EOL) software and hardware components in the supply chain?
Answer: By tracking EOL dates, planning replacements before support ends, and implementing compensating controls if immediate replacement is not possible
EOL components no longer receive security patches, so proactive replacement planning and compensating controls are essential to manage the associated risk.
What is the purpose of including supply chain security requirements in contracts with third-party service providers?
Answer: To legally obligate vendors to implement specified security controls and flow down those requirements to their subcontractors
Contractual security requirements ensure vendors are legally bound to maintain security standards and pass those requirements through their own supply chains.