Study. uk . com
  1. Home
  2. All questions
  3. Question 565

CompTIA Security+ study material · question 565 of 611

How does NIST expect supply chain cybersecurity to be handled?

  1. As a procurement checklist completed before purchase
  2. Integrated into existing risk management at every level of the organisation
  3. As a control family applied only to high-impact systems
  4. As a separate programme run by the legal team
Show the answer

Answer: B. Integrated into existing risk management at every level of the organisation

Treating it as a one-off purchasing step leaves the risk unmanaged for the life of the relationship.

Source: NIST SP 800-161 Rev. 1 (NIST) — SP 800-161 Rev. 1 › Abstract

Challenge yourself on this topic → Study as cards