Soru

Zorluk: OrtaThird-Party Risk Management and Supply Chain Oversight

An enterprise organization is updating its software supply chain oversight procedures. To prevent vulnerable open-source dependencies from entering its production environment, the security team requires third-party software providers to submit a formal, machine-readable inventory detailing all sub-components, libraries, and module versions included in their software releases. Which of the following artifacts should the security administrator mandate from vendors to satisfy this requirement?

  1. Software Bill of Materials (SBOM)Cevap
  2. B
    Business Associate Agreement (BAA)
  3. C
    Service Level Agreement (SLA)
  4. D
    Hardware Security Module (HSM) attestation

Cevap

The Software Bill of Materials (SBOM) is the required artifact because it provides a complete, machine-readable inventory of software components and third-party dependencies.
Requiring a Software Bill of Materials (SBOM) provides the organization with a standard, machine-readable manifest listing all software components, third-party libraries, and dependencies. This enables security teams to quickly query and assess supply chain risk when new vulnerabilities are reported in shared libraries.

Adım Adım Çözüm

1
Analyze the organizational requirement for third-party supply chain oversight.
The requirement specifies obtaining a machine-readable nested inventory of sub-components, libraries, and module versions within vendor software releases.
Tracking software dependencies is essential to identify zero-day or inherited open-source vulnerabilities across the supply chain.
2
Evaluate third-party agreement and operational documentation types against this specific requirement.
A Software Bill of Materials (SBOM) explicitly serves as a comprehensive manifest of all components and dependencies built into a software product.
Other artifacts focus on legal compliance (BAA), operational availability (SLA), or hardware cryptoprocessing (HSM attestation) rather than software composition analysis.

Anahtar Kavram

Software Bill of Materials (SBOM) for Supply Chain Oversight
Bu soruyu puanla