Soru

Zorluk: ZorThird-Party Risk Management and Supply Chain Oversight

An enterprise financial institution is preparing to integrate a third-party payment processing API into its core banking platform. During the vendor risk assessment, the security team notes that while the primary vendor adheres to strong internal security standards, the API relies on multiple embedded open-source components and downstream software dependencies. To continuously track, evaluate, and respond to vulnerabilities originating within these embedded components across the software deployment lifecycle, which of the following mechanisms should the security team require from the vendor?

  1. A Software Bill of Materials (SBOM) paired with continuous component vulnerability managementCevap
  2. B
    A SOC 2 Type I attestation report evaluating system availability and security control design
  3. C
    A Service Level Agreement (SLA) mandating sub-hour incident notification for operational outages
  4. D
    An Interconnection Security Agreement (ISA) defining encrypted transit channels for network data flow

Cevap

A Software Bill of Materials (SBOM) paired with continuous component vulnerability management
A Software Bill of Materials (SBOM) is a formal, structured record containing the details and supply chain relationships of various components used in building software. When combined with automated vulnerability management, it allows organizations to maintain complete visibility into nested third-party libraries and instantly identify exposed software components when new vulnerabilities are discovered.

Adım Adım Çözüm

1
Analyze the security risk presented in the scenario
Identified supply chain risk associated with nested open-source software dependencies in a third-party API
Security risks in third-party software often originate from downstream open-source components and libraries rather than the primary vendor's custom code alone.
2
Evaluate third-party risk management mechanisms for software supply chain transparency
Determined that a Software Bill of Materials (SBOM) provides the required nested inventory of software ingredients
An SBOM details all open-source modules, versions, and dependencies, enabling the purchasing organization to perform automated vulnerability matching against database records.
3
Select the appropriate artifact that enables continuous vulnerability oversight
Mandating an SBOM alongside continuous component vulnerability management ensures ongoing protection throughout the deployment lifecycle
Combining inventory visibility with continuous scanning enables rapid response when new zero-day vulnerabilities (e.g., CVEs) are disclosed in downstream dependencies.

Anahtar Kavram

Software Supply Chain Oversight and Software Bill of Materials (SBOM)
Bu soruyu puanla