CCSP · Question #221
Which ISO standard refers to addressing security risks in a supply chain?
The correct answer is B. ISO/IEC 28000:2007. ISO/IEC 28000:2007 is the specific standard addressing security management systems within the supply chain.
Question
Which ISO standard refers to addressing security risks in a supply chain?
Options
- AISO 27001
- BISO/IEC 28000:2007
- CISO 18799
- DISO 31000:2009
How the community answered
(51 responses)- A2% (1)
- B94% (48)
- D4% (2)
Why each option
ISO/IEC 28000:2007 is the specific standard addressing security management systems within the supply chain.
ISO 27001 specifies requirements for an Information Security Management System (ISMS) in general, not solely focused on the supply chain.
ISO/IEC 28000:2007 specifies requirements for a security management system, including aspects critical to ensuring security within the supply chain. This standard is specifically designed to help organizations manage and mitigate security risks across all stages of their supply chain operations.
ISO 18799 is not a recognized or relevant ISO standard for supply chain security.
ISO 31000:2009 provides general guidelines for risk management, applicable to any type of risk, but is not specific to supply chain security.
Concept tested: ISO standards for supply chain security
Source: https://www.iso.org/standard/41551.html
Topics
Community Discussion
No community discussion yet for this question.