CISSP - Security and Risk Management - Section 1.11

Apply Supply Chain Risk Management (SCRM) concepts including third-party assessment, minimum security requirements, and service-level requirements.

Apply Supply Chain Risk Management (SCRM) practices by assessing third-party risk, setting minimum security requirements, and defining service-level requirements for suppliers. Recognise how hardware integrity mechanisms such as silicon root of trust reduce the risk of tampered components entering the supply chain.

SCRMthird-party riskservice-level requirementsminimum security requirementssilicon root of trust

Practice question for this objective

Free sampleSecurity and Risk Managementmedium

A regional bank is preparing to onboard a new SaaS provider that will host a customer-facing loan origination workflow. The procurement team has signed a master services agreement, and the vendor has produced a current SOC 2 Type II report with no exceptions. The CISO is asked to approve the integration before go-live next quarter. What should the CISO do FIRST?

  • AApprove the onboarding on the strength of the clean SOC 2 Type II report and require annual re-attestation thereafter.
  • BCommission an independent penetration test of the vendor's production environment before any data is exchanged.
  • CRequire the vendor to add the bank as a named additional insured on its cyber liability policy and proceed.
  • DDefine the bank's minimum security requirements for the workflow and map the SOC 2 controls and contractual obligations against them to identify gaps. Correct
Recognise that third-party assurance evidence must be evaluated against the acquiring organisation's own minimum security requirements before onboarding. SCRM treats the acquirer's minimum security requirements as the yardstick: vendor attestations, contracts, and technical testing are inputs that must be compared to that baseline. Approving a provider on the basis of a SOC 2 report alone accepts the provider's chosen scope rather than the acquirer's risk-driven control set, leaving control gaps unmeasured.

Why A is wrong: A clean SOC 2 report is useful evidence but it reflects the vendor's chosen control set against AICPA criteria, not the bank's minimum security requirements for a loan origination system. Approval without mapping the report to the bank's own control baseline transfers unmeasured risk.

Why B is wrong: A penetration test is a useful technical assurance activity, but it tests a point-in-time configuration and is meaningless without first establishing what the bank requires the provider to protect and to what standard. It also typically requires the vendor's consent and scope agreement, which presupposes the baseline conversation.

Why C is wrong: Insurance is a financial risk transfer mechanism that addresses residual loss, not control adequacy. Naming the bank on the policy does nothing to confirm that the vendor meets the minimum security requirements for processing loan applicant data.

Why D is correct: SCRM expects the acquiring organisation to set its own minimum security requirements driven by the data classification and business process, then evaluate the provider's evidence and contract terms against that baseline. Gaps drive remediation, compensating controls, or risk acceptance before go-live.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Security and Risk Management objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.