Supply Chain Assessment Flashcards

1
Q

What is the purpose of supply chain assessment?

A

To mitigate the risks of the supply chain.

Every element (hardware, firmware, driver, OS, application) must be consistent and tamper resistant to create a trusted computing environment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Due Diligence?

A

A legal principle identifying that best practice or reasonable care has been used when setting up, configuring and maintaining a system.

Due diligence must be conducted by both/all parties cooperating together.

Due diligence should apply to all suppliers and contractors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When conducting your Due Diligence, what are you looking for?

A

Properly resourced cybersecurity program

Security assurance and risk management processes

Product support life cycle

Security controls for confidential data

Incident response and forensics assistance

General and historical company information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the Trusted Foundry?

A

A microprocessor manufacturing utility that is part of a validated supply chain. (One where hardware and software does not deviate from its documented function)

Essentially it’s a means to make sure that microprocessors are secure and trusted.

Created by the DoD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Hardware Source Authenticity?

A

Ensuring that hardware is obtained tamper-free from trustworthy suppliers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly