CISSP · Question #1461
An enterprise is developing a baseline cybersecurity standard its suppliers must meet before being awarded a contract. Which of the following statements is TRUE about the baseline cybersecurity…
The correct answer is C. It should be expressed in business terminology. A baseline cybersecurity standard for suppliers should be expressed in business terminology so that non-technical supplier stakeholders can understand and comply with the requirements.
Question
Options
- AIt should be expressed as general requirements.
- BIt should be expressed in legal terminology.
- CIt should be expressed in business terminology.
- DIt should be expressed as technical requirements.
How the community answered
(29 responses)- A7% (2)
- B3% (1)
- C76% (22)
- D14% (4)
Why each option
A baseline cybersecurity standard for suppliers should be expressed in business terminology so that non-technical supplier stakeholders can understand and comply with the requirements.
Expressing requirements as general requirements is too vague and provides insufficient specificity for suppliers to implement consistent, measurable controls, undermining the purpose of a baseline standard.
Legal terminology is appropriate for contracts and agreements but is not ideal for a cybersecurity baseline standard, as it can be ambiguous regarding specific security expectations and difficult for supplier security teams to interpret and implement.
Supplier-facing cybersecurity baseline standards must be written in business terminology because suppliers span diverse industries and may not have technical cybersecurity expertise. Business language ensures the requirements are understandable, actionable, and contractually enforceable across a broad supplier base without assuming technical knowledge. This approach aligns with supply chain risk management frameworks like NIST SP 800-161, which emphasize communicating requirements in terms meaningful to the business relationship.
Technical requirements are appropriate for internal IT or engineering teams but are unsuitable as the primary expression of a supplier baseline standard, since many supplier stakeholders lack the technical background needed to interpret and act on such language.
Concept tested: Supply chain cybersecurity baseline standard communication
Source: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.