CISSP GLOSSARY · RISK MANAGEMENT & GOVERNANCE

Supply Chain Risk Management (SCRM)

Identifying and reducing the risks inherited from suppliers, vendors, and service providers: tampered hardware, counterfeit components, malicious implants, and compromised updates.

Supply Chain Risk Management (SCRM) addresses the risks an organisation inherits from everyone upstream of it: hardware manufacturers, software vendors, cloud and service providers, and their suppliers in turn. The threats are distinctive: tampered equipment intercepted in transit, counterfeit components of unknown provenance, malicious implants added during manufacture, and compromised software updates arriving signed by a trusted vendor. A supplier’s weakness becomes your breach, as the SolarWinds compromise demonstrated at scale.

The caveat the exam tests is that you cannot outsource accountability. Contracts and due diligence reduce supplier risk, but the acquiring organisation still owns the consequences. Practical mitigations include third-party assessments and audits, minimum security requirements written into contracts, onsite reviews for critical suppliers, and a software bill of materials (SBOM) listing every component inside delivered software, the same inventory that software composition analysis automates for open-source dependencies.

Exam relevance: if a scenario involves risk arriving through a vendor, supplier, or acquired product, the answer space is SCRM: set minimum security requirements, assess before onboarding, and monitor for the life of the relationship. If the question mentions counterfeit or tampered hardware, the control is provenance verification through a trusted supply chain. Distinguish SCRM from internal risk treatment: the four responses still apply, but here the risk originates in an environment the organisation can neither inspect nor directly control.