CISSP - Security and Risk Management (16% of the exam) - Section 1.11

Apply Supply Chain Risk Management (SCRM) concepts including third-party assessment, minimum security requirements, and service-level requirements.

Apply Supply Chain Risk Management (SCRM) practices by assessing third-party risk, setting minimum security requirements, and defining service-level requirements for suppliers. Recognise how hardware integrity mechanisms such as silicon root of trust reduce the risk of tampered components entering the supply chain.

SCRMthird-party riskservice-level requirementsminimum security requirementssilicon root of trust

Practice question for this objective

Free sampleSecurity and Risk Managementmedium

A regional bank is preparing to onboard a new SaaS provider that will host a customer-facing loan origination workflow. The procurement team has signed a master services agreement, and the vendor has produced a current SOC 2 Type II report with no exceptions. The CISO is asked to approve the integration before go-live next quarter. What should the CISO do FIRST?

  • AApprove the onboarding on the strength of the clean SOC 2 Type II report and require annual re-attestation thereafter.
  • BCommission an independent penetration test of the vendor's production environment before any data is exchanged.
  • CRequire the vendor to add the bank as a named additional insured on its cyber liability policy and proceed.
  • DDefine the bank's minimum security requirements for the workflow and map the SOC 2 controls and contractual obligations against them to identify gaps. Correct
Recognise that third-party assurance evidence must be evaluated against the acquiring organisation's own minimum security requirements before onboarding. SCRM treats the acquirer's minimum security requirements as the yardstick: vendor attestations, contracts, and technical testing are inputs that must be compared to that baseline. Approving a provider on the basis of a SOC 2 report alone accepts the provider's chosen scope rather than the acquirer's risk-driven control set, leaving control gaps unmeasured.

Why A is wrong: A clean SOC 2 report is useful evidence but it reflects the vendor's chosen control set against AICPA criteria, not the bank's minimum security requirements for a loan origination system. Approval without mapping the report to the bank's own control baseline transfers unmeasured risk.

Why B is wrong: A penetration test is a useful technical assurance activity, but it tests a point-in-time configuration and is meaningless without first establishing what the bank requires the provider to protect and to what standard. It also typically requires the vendor's consent and scope agreement, which presupposes the baseline conversation.

Why C is wrong: Insurance is a financial risk transfer mechanism that addresses residual loss, not control adequacy. Naming the bank on the policy does nothing to confirm that the vendor meets the minimum security requirements for processing loan applicant data.

Why D is correct: SCRM expects the acquiring organisation to set its own minimum security requirements driven by the data classification and business process, then evaluate the provider's evidence and contract terms against that baseline. Gaps drive remediation, compensating controls, or risk acceptance before go-live.

See more CISSP practice questions, answers explained.

Exam traps in Security and Risk Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • A clause requiring the BPO to maintain a hot standby site in the same metropolitan region as the insurer's primary data centre.

    Why it is wrong: Geographic colocation can shorten failover but does not address confidentiality of PHI or the timeliness of breach notification under regulatory obligations. It is an availability control answering a confidentiality concern.

  • Immediately terminate the contract for cause and remove the microservice from production the same week to eliminate the exposure.

    Why it is wrong: Abrupt termination may be warranted later, but acting before assessment risks an unplanned outage of the telemetry pipeline and may breach the very contract that lacks a change-of-control clause. Risk management favours a controlled re-assessment before invoking termination remedies.

  • The vendor's published mean time between failures for the proposed server family across the last three product generations.

    Why it is wrong: MTBF speaks to reliability engineering, not to provenance or firmware integrity. A reliable server can still ship with a substituted component or a compromised firmware image, leaving the supply chain risk unaddressed.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.