Which framework provides guidelines for managing third-party cyber risk in supply chains?
- NIST SP 800-161
- ISO 27036
- Both A and B
- Neither
Answer: Both A and B
NIST SP 800-161 and ISO 27036 provide frameworks for supply chain risk management: vendor assessment, contract clauses, continuous monitoring. Critical for third-party risk governance questions.