nerdexam
Isaca

CGEIT · Question #609

Which of the following BEST enables an enterprise to minimize the risks of intellectual property theft and loss of sensitive information when acquiring Internet of Things (IoT) hardware and software c

The correct answer is D. Integrate supply chain cyber risk management processes. To minimize risks of intellectual property theft and sensitive information loss in IoT acquisition, an enterprise should integrate robust supply chain cyber risk management processes.

Submitted by luis.pe· Apr 18, 2026Risk Optimization

Question

Which of the following BEST enables an enterprise to minimize the risks of intellectual property theft and loss of sensitive information when acquiring Internet of Things (IoT) hardware and software components?

Options

  • AReview the data classification policy and relevant documentation
  • BTerminate contracts with suppliers from sanctioned regions of the world
  • CRequire nondisclosure agreements (NDAs) from all suppliers
  • DIntegrate supply chain cyber risk management processes

How the community answered

(59 responses)
  • A
    5% (3)
  • B
    14% (8)
  • C
    3% (2)
  • D
    78% (46)

Why each option

To minimize risks of intellectual property theft and sensitive information loss in IoT acquisition, an enterprise should integrate robust supply chain cyber risk management processes.

AReview the data classification policy and relevant documentation

Reviewing data classification policy and documentation is an internal control, but it doesn't directly address the *external* risk introduced by third-party IoT components from the supply chain.

BTerminate contracts with suppliers from sanctioned regions of the world

Terminating contracts with suppliers from sanctioned regions addresses geopolitical risks but is not a comprehensive cyber risk management strategy for all suppliers.

CRequire nondisclosure agreements (NDAs) from all suppliers

Requiring NDAs provides a legal protection layer but does not prevent the actual technical theft or loss of information if security vulnerabilities exist in the acquired components or the supplier's processes.

DIntegrate supply chain cyber risk management processesCorrect

Integrating supply chain cyber risk management processes provides a holistic approach to evaluating the security posture of IoT suppliers and their components, from design to deployment and disposal. This includes assessing their security controls, compliance, and potential vulnerabilities, thereby reducing the risk of IP theft and sensitive data loss inherent in third-party components.

Concept tested: IoT supply chain risk management

Topics

#Risk management#Supply chain security#IoT security#Information protection

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice