Akylade Certified Cyber Resilience Fundamentals ACCRF · Free Practice Question Medium
Question 3
An aeronautical engineering firm works primarily with the Department of Defense and relies heavily upon semiconductors that are manufactured outside the United States. They are concerned about the risk or attack surface associated with foreign made semiconductors. Which of the following subcategories in the NIST Cybersecurity Framework covers the firm’s concern?
- A Asset Management
- B Cybersecurity Supply Chain Risk Management
- C Data Security
- D Risk Assessment
Reveal correct answer
Correct answer: B
Explanation
Subcategories related to vendor risk assessment are primarily applied within the Cybersecurity Supply Chain Risk Management (GV.SC) category in the NIST Cybersecurity Framework. This category focuses on assessing and mitigating risks associated with the supply chain and external vendors. Risk Assessment (ID.RA) evaluates risks but may not specifically address vendor risks. Data Security (PR.DS) deals with safeguarding data but not necessarily vendor-related risk or risks related to the supply chain of a critical business. Asset Management (ID.AM) focuses on the identification and consistent management of assets that enable the organization to achieve business purposes relative to their importance to their organizational objectives and the organization’s risk strategy. For support or reporting issues, include Question ID: 6647afe671aee918de72bd59 in your ticket. Thank you.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
