An enterprise organization is procuring custom network appliances from a third-party manufacturer. To mitigate the risk of hardware supply chain tampering and unauthorized firmware modification during transit, the security team must establish a verification mechanism to validate device authenticity prior to deployment. Which of the following controls provides the MOST effective verification of hardware and firmware integrity upon receipt?
- Verifying the hardware root of trust and cryptographic signatures against the vendor's published measurements alongside a signed Software Bill of Materials (SBOM)Cevap
- BRequiring the third-party manufacturer to provide an annual SOC 2 Type II audit report certifying their physical facility security controls
- CExecuting an Interconnection Security Agreement (ISA) and Non-Disclosure Agreement (NDA) with the logistics provider delivering the hardware
- DPlacing the newly received network appliances into an isolated VLAN behind an inline Web Application Firewall (WAF) during initial staging
Cevap
Verifying the hardware root of trust and cryptographic signatures against the vendor's published measurements alongside a signed Software Bill of Materials (SBOM)
The correct answer provides cryptographic proof of hardware and firmware authenticity. A hardware root of trust (such as a Trusted Platform Module) combined with cryptographic signature verification against a vendor-provided Software Bill of Materials (SBOM) allows the receiving organization to detect unauthorized hardware additions, firmware alterations, or supply chain interdiction prior to connecting the device to the production environment.
Adım Adım Çözüm
Anahtar Kavram
Supply Chain Security and Hardware Integrity Verification