Supply Chain Risk Management Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Supply Chain Risk Management flashcards as text
What is Information and Communications Technology Supply Chain Risk Management (ICT SCRM)?
Answer: The process of identifying, assessing, and mitigating risks associated with the global supply chain for IT products and services
ICT SCRM addresses risks arising from the complex global supply chain, including malicious tampering, counterfeits, and vendor vulnerabilities.
Which NIST publication provides guidance specifically on supply chain risk management for federal systems?
Answer: NIST SP 800-161
NIST SP 800-161 provides guidance on identifying and mitigating supply chain risks for federal information systems and organizations.
Which NIST SP 800-53 control family specifically addresses supply chain risk management?
Answer: SR (Supply Chain Risk Management)
The SR control family, added in NIST SP 800-53 Revision 5, specifically addresses supply chain risk management controls.
What is a 'counterfeit component' threat in the context of ICT supply chain risk?
Answer: Hardware or software that is fraudulently represented as genuine but may contain malicious functionality or quality defects
Counterfeit components are fake products that may contain backdoors, poor quality components, or malicious code inserted during manufacturing.
What is a Software Bill of Materials (SBOM) and why is it important for supply chain security?
Answer: A formal record of software components and their dependencies, enabling organizations to identify vulnerable libraries quickly
An SBOM provides transparency into a software product's components, helping organizations rapidly identify exposure when vulnerabilities like Log4Shell are discovered.
Which executive order significantly elevated the importance of software supply chain security for federal agencies?
Answer: Executive Order 14028 (Improving the Nation's Cybersecurity)
EO 14028, issued in May 2021, directed federal agencies to improve supply chain security, requiring SBOMs and secure software development practices.