A city is selecting a court e-filing SaaS provider. Which SCRM mitigation set best fits the procurement security requirements?
Select an answer to reveal the explanation.
Short Explanation
For court e-filing, trust but verify with real SCRM levers: assessments, written minimums, and SBOMs when they fit. Glossy PDFs are not assurance. Put the expectations in the deal before go-live.
Full Explanation
SCRM mitigations include third-party security assessments and monitoring, contractual minimum security requirements, and transparency artifacts such as SBOMs for relevant software. These reduce uncertainty about vendor posture and components. Brochure claims without assessment rights or enforceable requirements leave residual supply-chain risk unmanaged.