ISP Supply Chain Security & Vendor Management 2 — Questions and Answers
Question 1: Which of the following is the BEST method for evaluating a new vendor's security posture before awarding a contract?
- Reviewing the vendor's marketing materials and website
- Conducting a third-party security audit or requiring completion of a standardized security questionnaire (Correct answer)
- Checking the vendor's social media presence
- Relying solely on the vendor's self-reported compliance status
Correct answer: Conducting a third-party security audit or requiring completion of a standardized security questionnaire
Third-party audits or standardized questionnaires (such as NIST SP 800-161 aligned assessments) provide objective, verifiable evidence of a vendor's security controls.
Question 2: Under NIST SP 800-161, what is the primary purpose of a Supplier Risk Assessment?
- To negotiate lower prices with suppliers
- To identify, assess, and mitigate cybersecurity and supply chain risks posed by ICT suppliers (Correct answer)
- To audit a supplier's financial stability only
- To eliminate all foreign-sourced components
Correct answer: To identify, assess, and mitigate cybersecurity and supply chain risks posed by ICT suppliers
NIST SP 800-161 specifically guides organizations in identifying, assessing, and mitigating risks that information and communications technology (ICT) suppliers introduce into the supply chain.
Question 3: A critical industrial facility learns that its SCADA software vendor will reach end-of-life (EOL) in six months with no patches thereafter. What is the MOST appropriate response?
- Continue operations with the EOL software and monitor for issues
- Immediately shut down all SCADA systems
- Develop a migration plan to supported software while implementing compensating controls during transition (Correct answer)
- Request the vendor extend support indefinitely at no cost
Correct answer: Develop a migration plan to supported software while implementing compensating controls during transition
A structured migration plan with compensating controls (such as enhanced monitoring and network segmentation) addresses the risk while maintaining operational continuity during the transition.
Question 4: Which clause in a vendor contract BEST helps protect an organization if a supplier experiences a security incident?
- Force majeure clause
- Security breach notification requirement clause (Correct answer)
- Net-30 payment terms clause
- Exclusivity clause
Correct answer: Security breach notification requirement clause
A security breach notification requirement obligates the vendor to promptly inform the organization of incidents, enabling timely response and mitigation of downstream impacts.
Question 5: What is 'supply chain transparency' and why is it important for industrial security professionals?
- Publishing all procurement costs publicly to deter fraud
- The ability to trace components and services back to their origin to verify authenticity and integrity (Correct answer)
- Allowing all employees to view vendor contracts
- Sharing proprietary supplier lists with industry partners
Correct answer: The ability to trace components and services back to their origin to verify authenticity and integrity
Supply chain transparency enables organizations to verify where materials originate, detect tampering or counterfeiting, and ensure components meet security and quality standards.
Question 6: Which of the following BEST describes a 'trusted supplier program' in an industrial security context?
- A marketing program where suppliers pay for a certification badge
- A formal vetting and approval process that authorizes suppliers to provide goods or services with reduced oversight (Correct answer)
- A program requiring all suppliers to be located domestically
- A financial incentive program for suppliers who meet delivery deadlines
Correct answer: A formal vetting and approval process that authorizes suppliers to provide goods or services with reduced oversight
A trusted supplier program formally vets and approves suppliers based on security criteria, allowing the organization to reduce redundant controls for pre-approved vendors while maintaining assurance.
Question 7: When conducting a supply chain risk assessment, which factor is MOST critical when evaluating a foreign-based supplier?
- The supplier's geographic proximity to the nearest airport
- Whether the supplier's country of origin has laws that could compel disclosure of sensitive information or data (Correct answer)
- The supplier's number of employees
- The local currency exchange rate
Correct answer: Whether the supplier's country of origin has laws that could compel disclosure of sensitive information or data
Laws in certain foreign jurisdictions can compel suppliers to disclose sensitive data or provide backdoor access to governments, representing a significant supply chain intelligence risk.
Which of the following is the BEST method for evaluating a new vendor's security posture before awarding a contract?