From the course: CSSLP Cert Prep: 8 Supply Chain and Software Acquisition

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Monitor risks over time

Monitor risks over time

From the course: CSSLP Cert Prep: 8 Supply Chain and Software Acquisition

Start my 1-month free trial

Monitor risks over time

- [Instructor] A supply chain risk assessment isn't a one and done exercise. Another key step in reducing your exposure to these risks is monitoring them over time as well as starting the assessment cycle again as risk profiles change. This is an important distinction that separates those organizations who improve their supply chain security over time from those who are more likely to suffer from a software supply chain security incident. When you perform a supply chain risk assessment, you're conducting a point-in-time activity that results in a snapshot of your risk exposure. Organizations often conduct these types of assessments at least once a year. Yes, there's tremendous value in this exercise, but those risks are going to change over time. Ideally, your exposure to those risks will decrease as you and your team take corrective actions, but changes in your supply chain, your operations, and even in newly disclosed…

Contents