<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Supply chain risk management (SCRM) in CISSP Study Group</title>
    <link>https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/m-p/74133#M1701</link>
    <description>&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 27 Sep 2024 04:15:38 GMT</pubDate>
    <dc:creator>Mahender</dc:creator>
    <dc:date>2024-09-27T04:15:38Z</dc:date>
    <item>
      <title>Supply chain risk management (SCRM)</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/m-p/73979#M1678</link>
      <description>&lt;P&gt;14. Supply chain risk management (SCRM) is a means to ensure that all the vendors or links in&lt;BR /&gt;the supply chain are reliable, trustworthy, reputable organizations. Which of the following&lt;BR /&gt;are true statements? (Choose all that apply.)&lt;BR /&gt;A. Each link in the supply chain should be responsible and accountable to the next link in&lt;BR /&gt;the chain.&lt;BR /&gt;B. Commodity vendors are unlikely to have mined their own metals or processed the oil for&lt;BR /&gt;plastics or etched the silicon of their chips.&lt;BR /&gt;C. If the final product derived from a supply chain meets expectations and functional&lt;BR /&gt;requirements, it is assured to not have unauthorized elements.&lt;BR /&gt;D. Failing to properly secure a supply chain can result in flawed or less reliable products, or&lt;BR /&gt;even embedded listing or remote control mechanisms.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The answer given in ISC2 is&amp;nbsp;A, B, D, but I believe the correct answer is A and D. Please correct me if I am wrong.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 10:57:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/m-p/73979#M1678</guid>
      <dc:creator>Mahender</dc:creator>
      <dc:date>2024-09-20T10:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Supply chain risk management (SCRM)</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/m-p/73981#M1679</link>
      <description>&lt;P&gt;Companies buy materials which are used to make other products, because making products is &lt;EM&gt;their&lt;/EM&gt; business.&amp;nbsp; Extracting / mining / procuring is someone else's business entirely.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, buying materials means the purchaser are abstracted from a thorough knowledge of the provenance of the raw materials.&amp;nbsp; If a purchaser orders heavy sweet crude oil, and the vendor sends light sweet crude oil, they will not be able to make any products which require heavy sweet crude.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's a very simplified answer, of course.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 11:35:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/m-p/73981#M1679</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2024-09-20T11:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Supply chain risk management (SCRM)</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/m-p/73992#M1684</link>
      <description>&lt;P&gt;So, you mean the answer is A &amp;amp; D alone?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 13:21:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/m-p/73992#M1684</guid>
      <dc:creator>Mahender</dc:creator>
      <dc:date>2024-09-20T13:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Supply chain risk management (SCRM)</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/m-p/73997#M1685</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;The ISC2 answer of A, B, and D is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let’s break down why statement B is accurate:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Statement B: Commodity vendors are unlikely to have mined their own metals or processed the oil for plastics or etched the silicon of their chips.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This statement highlights the complexity and specialization within supply chains. Commodity vendors typically source raw materials from various suppliers rather than producing them themselves. For example:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Metals&lt;/STRONG&gt;: A vendor selling metal components is unlikely to have mined the ore themselves. Instead, they purchase raw metals from mining companies.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Plastics&lt;/STRONG&gt;: Similarly, a vendor providing plastic parts is unlikely to have processed the crude oil into plastic. They buy processed plastic from chemical companies.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Silicon chips&lt;/STRONG&gt;: Vendors selling silicon chips usually purchase silicon wafers from specialized manufacturers who handle the intricate process of etching silicon.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;A class="" href="https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/td-p/73979" target="_blank" rel="noopener"&gt;This separation of roles is common in supply chains, where different stages of production are handled by specialized entities&lt;/A&gt;&lt;A class="" href="https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/td-p/73979" target="_blank" rel="noopener"&gt;1&lt;/A&gt;&lt;A class="" href="https://www.mckinsey.com/capabilities/operations/our-insights/a-practical-approach-to-supply-chain-risk-management" target="_blank" rel="noopener"&gt;2&lt;/A&gt;. This specialization allows each entity to focus on their core competencies, leading to more efficient and cost-effective production processes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Why B is correct:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A class="" href="https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/td-p/73979" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Specialization&lt;/STRONG&gt;: Each link in the supply chain focuses on specific tasks, leading to efficiency and expertise in those areas&lt;/A&gt;&lt;A class="" href="https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/td-p/73979" target="_blank" rel="noopener"&gt;1&lt;/A&gt;.&lt;/LI&gt;&lt;LI&gt;&lt;A class="" href="https://www.mckinsey.com/capabilities/operations/our-insights/a-practical-approach-to-supply-chain-risk-management" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Complexity&lt;/STRONG&gt;: Modern supply chains are highly complex, with multiple layers of suppliers and sub-suppliers&lt;/A&gt;&lt;A class="" href="https://www.mckinsey.com/capabilities/operations/our-insights/a-practical-approach-to-supply-chain-risk-management" target="_blank" rel="noopener"&gt;2&lt;/A&gt;. It’s impractical for a single vendor to manage all stages of production.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Sources:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A class="" href="https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/td-p/73979" target="_blank" rel="noopener"&gt;McKinsey’s practical approach to supply-chain risk management&lt;/A&gt;&lt;A class="" href="https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/td-p/73979" target="_blank" rel="noopener"&gt;1&lt;/A&gt;.&lt;/LI&gt;&lt;LI&gt;&lt;A class="" href="https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/td-p/73979" target="_blank" rel="noopener"&gt;UpGuard’s explanation of supply chain risk management&lt;/A&gt;&lt;A class="" href="https://www.mckinsey.com/capabilities/operations/our-insights/a-practical-approach-to-supply-chain-risk-management" target="_blank" rel="noopener"&gt;2&lt;/A&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I hope this clarifies why statement B is included as a correct answer.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 20 Sep 2024 14:22:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/m-p/73997#M1685</guid>
      <dc:creator>VincentNgVS</dc:creator>
      <dc:date>2024-09-20T14:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Supply chain risk management (SCRM)</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/m-p/74133#M1701</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 04:15:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/Supply-chain-risk-management-SCRM/m-p/74133#M1701</guid>
      <dc:creator>Mahender</dc:creator>
      <dc:date>2024-09-27T04:15:38Z</dc:date>
    </item>
  </channel>
</rss>

