CGEIT · Question #609
Which of the following BEST enables an enterprise to minimize the risks of intellectual property theft and loss of sensitive information when acquiring Internet of Things (IoT) hardware and software c
The correct answer is D. Integrate supply chain cyber risk management processes. To minimize risks of intellectual property theft and sensitive information loss in IoT acquisition, an enterprise should integrate robust supply chain cyber risk management processes.
Question
Which of the following BEST enables an enterprise to minimize the risks of intellectual property theft and loss of sensitive information when acquiring Internet of Things (IoT) hardware and software components?
Options
- AReview the data classification policy and relevant documentation
- BTerminate contracts with suppliers from sanctioned regions of the world
- CRequire nondisclosure agreements (NDAs) from all suppliers
- DIntegrate supply chain cyber risk management processes
How the community answered
(59 responses)- A5% (3)
- B14% (8)
- C3% (2)
- D78% (46)
Why each option
To minimize risks of intellectual property theft and sensitive information loss in IoT acquisition, an enterprise should integrate robust supply chain cyber risk management processes.
Reviewing data classification policy and documentation is an internal control, but it doesn't directly address the *external* risk introduced by third-party IoT components from the supply chain.
Terminating contracts with suppliers from sanctioned regions addresses geopolitical risks but is not a comprehensive cyber risk management strategy for all suppliers.
Requiring NDAs provides a legal protection layer but does not prevent the actual technical theft or loss of information if security vulnerabilities exist in the acquired components or the supplier's processes.
Integrating supply chain cyber risk management processes provides a holistic approach to evaluating the security posture of IoT suppliers and their components, from design to deployment and disposal. This includes assessing their security controls, compliance, and potential vulnerabilities, thereby reducing the risk of IP theft and sensitive data loss inherent in third-party components.
Concept tested: IoT supply chain risk management
Topics
Community Discussion
No community discussion yet for this question.