CAP Supply Chain Risk Management 1 — Questions and Answers
Question 1: What is Information and Communications Technology Supply Chain Risk Management (ICT SCRM)?
- The process of identifying, assessing, and mitigating risks associated with the global supply chain for IT products and services (Correct answer)
- Managing vendor contracts for software licenses only
- Auditing the source code of all purchased applications
- Verifying that all hardware is manufactured domestically
Correct answer: The process of identifying, assessing, and mitigating risks associated with the global supply chain for IT products and services
ICT SCRM addresses risks arising from the complex global supply chain, including malicious tampering, counterfeits, and vendor vulnerabilities.
Question 2: Which NIST publication provides guidance specifically on supply chain risk management for federal systems?
- NIST SP 800-161 (Correct answer)
- NIST SP 800-53
- NIST SP 800-171
- NIST SP 800-37
Correct answer: NIST SP 800-161
NIST SP 800-161 provides guidance on identifying and mitigating supply chain risks for federal information systems and organizations.
Question 3: Which NIST SP 800-53 control family specifically addresses supply chain risk management?
- SR (Supply Chain Risk Management) (Correct answer)
- SA (System and Services Acquisition)
- CA (Assessment, Authorization, and Monitoring)
- PM (Program Management)
Correct answer: SR (Supply Chain Risk Management)
The SR control family, added in NIST SP 800-53 Revision 5, specifically addresses supply chain risk management controls.
Question 4: What is a 'counterfeit component' threat in the context of ICT supply chain risk?
- Hardware or software that is fraudulently represented as genuine but may contain malicious functionality or quality defects (Correct answer)
- A software license purchased from an unauthorized reseller
- A configuration setting that deviates from vendor defaults
- An outdated firmware version that has known vulnerabilities
Correct answer: Hardware or software that is fraudulently represented as genuine but may contain malicious functionality or quality defects
Counterfeit components are fake products that may contain backdoors, poor quality components, or malicious code inserted during manufacturing.
Question 5: What is a Software Bill of Materials (SBOM) and why is it important for supply chain security?
- A formal record of software components and their dependencies, enabling organizations to identify vulnerable libraries quickly (Correct answer)
- A vendor contract listing all software covered under a license agreement
- A government-mandated list of approved software vendors
- A log of all software changes made during system development
Correct answer: A formal record of software components and their dependencies, enabling organizations to identify vulnerable libraries quickly
An SBOM provides transparency into a software product's components, helping organizations rapidly identify exposure when vulnerabilities like Log4Shell are discovered.
Question 6: Which executive order significantly elevated the importance of software supply chain security for federal agencies?
- Executive Order 14028 (Improving the Nation's Cybersecurity) (Correct answer)
- Executive Order 13636 (Improving Critical Infrastructure Cybersecurity)
- Executive Order 13800 (Strengthening Federal Networks)
- Executive Order 12333 (United States Intelligence Activities)
Correct answer: Executive Order 14028 (Improving the Nation's Cybersecurity)
EO 14028, issued in May 2021, directed federal agencies to improve supply chain security, requiring SBOMs and secure software development practices.
What is Information and Communications Technology Supply Chain Risk Management (ICT SCRM)?