Soru

Zorluk: KolayThird-Party Risk Management and Supply Chain Oversight

An organization is preparing to onboard a new software-as-a-service (SaaS) vendor to process sensitive financial records. Which of the following activities are essential steps in performing third-party risk management and supply chain oversight during vendor assessment? (Select TWO).

  1. Reviewing the vendor's SOC 2 Type II report to evaluate operational security controls over an extended periodCevap
  2. Requesting and analyzing the vendor's Software Bill of Materials (SBOM) to verify third-party library dependenciesCevap
  3. C
    Configuring local firewall rules directly on the cloud provider's internal application servers
  4. D
    Reclassifying vendor API traffic as trusted internal traffic to bypass secondary identity verification
  5. E
    Eliminating Service Level Agreements (SLAs) from contracts to streamline vendor onboarding timelines

Cevap

Reviewing the vendor's SOC 2 Type II report and analyzing the vendor's Software Bill of Materials (SBOM) are key elements of third-party risk management and supply chain oversight.
Reviewing independent audit attestations like SOC 2 Type II reports verifies that the vendor maintains effective security controls over time. Evaluating a Software Bill of Materials (SBOM) provides critical visibility into open-source components and software supply chain vulnerabilities.

Adım Adım Çözüm

1
Identify effective third-party governance mechanisms
Independent audit attestations (SOC 2 Type II) confirm that operational security controls work continuously over time.
Third-party risk management relies on independent verification of security posture.
2
Identify software supply chain integrity controls
Obtaining an SBOM allows the organization to track nested dependencies and mitigate supply chain vulnerabilities.
Supply chain oversight requires visibility into embedded third-party libraries and packages.

Anahtar Kavram

Third-Party Risk Management and Supply Chain Oversight
Bu soruyu puanla