ISP Supply Chain Security & Vendor Management 1 — Questions and Answers
Question 1: Which of the following BEST describes the primary goal of supply chain security in an industrial environment?
- Reducing procurement costs through vendor consolidation
- Ensuring integrity, authenticity, and continuity of goods and services throughout the supply chain (Correct answer)
- Automating vendor contract negotiations
- Limiting the number of approved suppliers to two or fewer
Correct answer: Ensuring integrity, authenticity, and continuity of goods and services throughout the supply chain
Supply chain security aims to protect the integrity, authenticity, and continuity of products and services from origin through delivery to the end user.
Question 2: A company discovers that a critical component supplier has been acquired by a foreign entity with potential ties to a nation-state adversary. What is the MOST appropriate immediate action?
- Continue business as usual until the next contract renewal
- Conduct a supply chain risk assessment and consider alternative suppliers (Correct answer)
- Immediately terminate the contract without further review
- Report the acquisition to the media
Correct answer: Conduct a supply chain risk assessment and consider alternative suppliers
A supply chain risk assessment allows the organization to evaluate the actual threat level and develop an informed mitigation strategy, including identifying alternative suppliers if necessary.
Question 3: Which federal regulation requires contractors handling classified information to implement supply chain risk management (SCRM) practices?
- OSHA 1910.119
- NISPOM (32 CFR Part 117) (Correct answer)
- HIPAA Security Rule
- SOX Section 404
Correct answer: NISPOM (32 CFR Part 117)
The National Industrial Security Program Operating Manual (NISPOM), codified at 32 CFR Part 117, governs cleared contractors and includes supply chain risk management requirements.
Question 4: What is a 'counterfeit part' in the context of supply chain security?
- A part manufactured by an unapproved domestic supplier
- An item that is a copy, imitation, or substitute that has been misrepresented as genuine (Correct answer)
- A surplus part sold at a reduced price
- A part that fails quality inspection due to manufacturing defects
Correct answer: An item that is a copy, imitation, or substitute that has been misrepresented as genuine
A counterfeit part is misrepresented as genuine or authorized, posing safety and security risks especially in critical industrial systems.
Question 5: Which of the following is an example of a SECOND-TIER supply chain risk?
- A direct vendor failing to deliver on time
- A subcontractor used by your primary vendor experiencing a data breach (Correct answer)
- An internal employee misusing procurement credentials
- A natural disaster affecting your own facility
Correct answer: A subcontractor used by your primary vendor experiencing a data breach
Second-tier (or sub-tier) risks involve suppliers of your suppliers; a subcontractor breach can propagate vulnerabilities up through your primary vendor to your organization.
Question 6: Which practice is MOST effective in verifying the authenticity of hardware components received from a supplier?
- Accepting the supplier's certificate of conformance without inspection
- Visual inspection only by receiving staff
- Testing against known-good baselines and reviewing traceability documentation (Correct answer)
- Storing components in a secure warehouse for 30 days before use
Correct answer: Testing against known-good baselines and reviewing traceability documentation
Testing against known-good baselines and verifying traceability documentation (including provenance records) are the most effective methods for detecting counterfeit or tampered components.
Question 7: What does the term 'vendor lock-in' represent as a supply chain security concern?
- A vendor physically securing their facility
- Excessive dependence on a single vendor that limits an organization's ability to switch suppliers (Correct answer)
- A contractual clause preventing vendors from disclosing pricing
- A security feature that limits vendor system access
Correct answer: Excessive dependence on a single vendor that limits an organization's ability to switch suppliers
Vendor lock-in creates a single point of failure and reduces negotiating leverage, making the organization vulnerable if that vendor is compromised, disrupted, or becomes adversarial.
Which of the following BEST describes the primary goal of supply chain security in an industrial environment?