Soru

Zorluk: OrtaThird-Party Risk Management and Supply Chain Oversight

An enterprise organization is procuring core networking hardware from an external supplier to deploy in a high-security data center. The security team wants to prevent threat actors from intercepting the physical shipment to install malicious microcode or physical implants during transit. Which supply chain security control should the organization mandate to address this specific risk?

  1. Mandate hardware provenance tracking using tamper-evident packaging and verified physical chain-of-custody attestations.Cevap
  2. B
    Require the vendor to execute a software escrow agreement for all underlying device firmware.
  3. C
    Obtain an annual SOC 2 Type I audit report detailing the vendor's physical data center access security controls.
  4. D
    Incorporate a mutual non-disclosure agreement (NDA) into the vendor contract prior to shipment.

Cevap

Mandating hardware provenance tracking using tamper-evident packaging and verified physical chain-of-custody attestations is the correct supply chain control.
Establishing physical chain of custody along with tamper-evident seals ensures that any unauthorized opening, inspection, or modification of hardware during shipment is detectable prior to deployment.

Adım Adım Çözüm

1
Analyze the threat context in the scenario.
The risk involves physical interdiction, microcode tampering, or hardware implant insertion during the transit of physical equipment from supplier to customer.
Identifying the specific threat vector guides the selection of targeted supply chain security controls.
2
Evaluate potential supply chain controls against physical transit tampering.
Chain-of-custody logs ensure end-to-end accountability of handlers, while tamper-evident packaging provides visual and physical verification that shipments have not been compromised en route.
Effective supply chain oversight relies on verifiable physical and cryptographical controls at each logistics step.
3
Differentiate correct supply chain protections from non-applicable administrative or continuity agreements.
Administrative contracts such as NDAs, software escrow, and service provider SOC audit reports address confidentiality, business continuity, and operational governance rather than hardware transit security.
Controls must match the specific operational domain and failure mode described.

Anahtar Kavram

Supply Chain Hardware Oversight and Provenance
Tahmini Süre:1m 15s
Bu soruyu puanla