An organization is preparing to onboard a new software-as-a-service (SaaS) vendor to process sensitive financial records. Which of the following activities are essential steps in performing third-party risk management and supply chain oversight during vendor assessment? (Select TWO).
- Reviewing the vendor's SOC 2 Type II report to evaluate operational security controls over an extended periodAnswer
- Requesting and analyzing the vendor's Software Bill of Materials (SBOM) to verify third-party library dependenciesAnswer
- CConfiguring local firewall rules directly on the cloud provider's internal application servers
- DReclassifying vendor API traffic as trusted internal traffic to bypass secondary identity verification
- EEliminating Service Level Agreements (SLAs) from contracts to streamline vendor onboarding timelines
Answer
Reviewing the vendor's SOC 2 Type II report and analyzing the vendor's Software Bill of Materials (SBOM) are key elements of third-party risk management and supply chain oversight.
Reviewing independent audit attestations like SOC 2 Type II reports verifies that the vendor maintains effective security controls over time. Evaluating a Software Bill of Materials (SBOM) provides critical visibility into open-source components and software supply chain vulnerabilities.
Step-by-Step Solution
Key Concept
Third-Party Risk Management and Supply Chain Oversight