FedRAMP FedRAMP Third-Party Assessment & Supply Chain 2 — Questions and Answers
Question 1: Which NIST publication specifically addresses supply chain risk management for federal information systems?
- NIST SP 800-161 (Correct answer)
- NIST SP 800-53
- NIST SP 800-37
- NIST SP 800-137
Correct answer: NIST SP 800-161
NIST SP 800-161 (Cybersecurity Supply Chain Risk Management Practices) specifically addresses managing supply chain risks for federal systems.
Question 2: When a 3PAO conducts penetration testing for a FedRAMP assessment, what is the primary objective?
- To attempt to exploit vulnerabilities and validate whether security controls prevent unauthorized access (Correct answer)
- To scan for open ports and document the network topology
- To review policy documents and verify compliance with NIST standards
- To test the disaster recovery plan and backup restoration procedures
Correct answer: To attempt to exploit vulnerabilities and validate whether security controls prevent unauthorized access
FedRAMP penetration testing attempts to exploit identified vulnerabilities to determine if security controls effectively prevent unauthorized access.
Question 3: What is the purpose of an interconnection security agreement (ISA) in the FedRAMP context?
- To formally document the security requirements and responsibilities when two systems share data or connectivity (Correct answer)
- To authorize users to access interconnected cloud systems
- To replace the need for a 3PAO assessment when systems are interconnected
- To document the technical specifications of network hardware
Correct answer: To formally document the security requirements and responsibilities when two systems share data or connectivity
An ISA formally defines the security controls, data flows, and responsibilities when a FedRAMP system connects to another system.
Question 4: What FedRAMP supply chain control requires CSPs to assess and manage risks from open-source software components?
- SA-12 (Supply Chain Protection) and related controls requiring software bill of materials practices (Correct answer)
- AC-2 (Account Management)
- IR-4 (Incident Handling)
- CA-7 (Continuous Monitoring)
Correct answer: SA-12 (Supply Chain Protection) and related controls requiring software bill of materials practices
FedRAMP's SA-12 and related supply chain controls require CSPs to identify and manage risks from all software components, including open-source libraries.
Question 5: What is a Software Bill of Materials (SBOM) and why is it important in FedRAMP supply chain security?
- An inventory of software components and dependencies that helps identify vulnerable or malicious code in the supply chain (Correct answer)
- A procurement document listing all licensed software used by the CSP
- A report generated by 3PAOs documenting software misconfigurations
- A log of all software changes deployed to the production environment
Correct answer: An inventory of software components and dependencies that helps identify vulnerable or malicious code in the supply chain
An SBOM is a comprehensive inventory of all software components, enabling identification and response to vulnerabilities in third-party dependencies.
Question 6: In FedRAMP, what must a CSP do when a critical vulnerability is discovered in a third-party component used in their authorized system?
- Remediate within the FedRAMP-required timeframe and report in the POA&M and continuous monitoring deliverables (Correct answer)
- Immediately revoke the authorization and begin re-authorization
- Wait for the third-party vendor to release a patch before taking action
- Report only to the 3PAO without notifying the authorizing agency
Correct answer: Remediate within the FedRAMP-required timeframe and report in the POA&M and continuous monitoring deliverables
CSPs must remediate critical vulnerabilities within FedRAMP's required timeframes (typically 30 days) and track them in the POA&M with continuous monitoring reporting.
Which NIST publication specifically addresses supply chain risk management for federal information systems?