nerdexam
(ISC)2

CCSP · Question #221

Which ISO standard refers to addressing security risks in a supply chain?

The correct answer is B. ISO/IEC 28000:2007. ISO/IEC 28000:2007 is the specific standard addressing security management systems within the supply chain.

Submitted by carter_n· Apr 18, 2026Legal, Risk and Compliance

Question

Which ISO standard refers to addressing security risks in a supply chain?

Options

  • AISO 27001
  • BISO/IEC 28000:2007
  • CISO 18799
  • DISO 31000:2009

How the community answered

(51 responses)
  • A
    2% (1)
  • B
    94% (48)
  • D
    4% (2)

Why each option

ISO/IEC 28000:2007 is the specific standard addressing security management systems within the supply chain.

AISO 27001

ISO 27001 specifies requirements for an Information Security Management System (ISMS) in general, not solely focused on the supply chain.

BISO/IEC 28000:2007Correct

ISO/IEC 28000:2007 specifies requirements for a security management system, including aspects critical to ensuring security within the supply chain. This standard is specifically designed to help organizations manage and mitigate security risks across all stages of their supply chain operations.

CISO 18799

ISO 18799 is not a recognized or relevant ISO standard for supply chain security.

DISO 31000:2009

ISO 31000:2009 provides general guidelines for risk management, applicable to any type of risk, but is not specific to supply chain security.

Concept tested: ISO standards for supply chain security

Source: https://www.iso.org/standard/41551.html

Topics

#ISO standards#Supply chain security#Risk management#Compliance

Community Discussion

No community discussion yet for this question.

Full CCSP Practice