An organization is hardening its network architecture against supply chain attacks targeting third-party software dependencies and vendor integrations. Which TWO best practices and controls should be implemented? (Choose TWO)
SBOM and SCA tools track third-party dependencies and identify known vulnerabilities.
Why this answer
Supply chain security is reinforced by performing Software Bill of Materials (SBOM) tracking and software composition analysis (SCA) to identify vulnerable dependencies, alongside enforcing strict vendor risk management and access controls.