1-11 Flashcards

1
Q

Who are the 4 participants in the supply chain?

A

Suppliers, Distributors, Manufacturers, and Retailers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How are supply chains infiltrated?

A

Software: compromise development, malicious code injection, update tampering. Hardware: Tampering with manufacturing, inserting malicious components, counterfeits.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are some ways to mitigate Supply Chain Risks?

A

Diversify suppliers, develop contingency plans, collaborate with key stakeholders across the supply chain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is SCRM?

A

Supply chain risk management - implementation of strategies to manage uncertainty, identify vulnerabilities, mitigate risks, and ensure continuity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are some SCRM endevours?

A
  • Strategic alignment with enterprise risk management program.
    • Supply chain due diligence. Investigating as many layers in supply chain as much as possible
    • Dual or multi sourcing whenever possible.
    • Supply chain security mechanisms.
      Contracts and agreements.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a Silicon Root of Trust?

A

Cryptographic hardware security module. Device integrity, secure boot, attestation, authentication, and lifecycle security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a PUF?

A

Physically Unclonable Function - Unique and hard to replicate hardware identifier

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is an SBOM?

A

Software Bill of Materials: Very detailed list of components, libraries, cryptographic signatures, and metadata used in software development of a software application.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly