When evaluating supply chain risk for a critical software component, what is the MOST significant concern regarding a third-party vendor that has poor security practices and lacks transparent security audits?
Correct Answer: Increased risk of software vulnerabilities or backdoors being introduced Explanation: Poor security practices and a lack of transparency in a supply chain vendor significantly increase the risk that their software components could contain unaddressed vulnerabilities, malware, or even intentional backdoors, which would then be inherited by the purchasing organization.
Correct Answer: Increased risk of software vulnerabilities or backdoors being introduced Explanation: Poor security practices and a lack of transparency in a supply chain vendor significantly increase the risk that their software components could contain unaddressed vulnerabilities, malware, or even intentional backdoors, which would then be inherited by the purchasing organization.