1. A company is concerned with supply chain compromise of new servers and wants to limit this risk. Which of the following should the company review first?

Answer: B

Explanation:

The company should review the acquisition process first.

Reviewing the acquisition process is essential for mitigating supply chain risks associated with new servers. By ensuring that the procurement methods and vendor selections are secure and reliable, the company can prevent potential compromises before they occur.

A) Sanitization procedure

While sanitization procedures are important for protecting data on existing assets, they are not the first line of defense against supply chain compromises. Focusing on sanitization would be more relevant after the acquisition process has ensured that secure servers are obtained.

B) Acquisition process

The acquisition process is crucial because it directly addresses how the company sources new servers. By assessing vendors, evaluating their security practices, and ensuring compliance with standards, the company can significantly reduce the risk of receiving compromised equipment.

C) Change management

Change management is important for controlling modifications to systems and processes, but it comes into play after the servers have already been acquired. Addressing supply chain issues must occur prior to implementing changes, making this option less relevant in the context of initial risk mitigation.

D) Asset tracking

Asset tracking is vital for managing and monitoring IT assets throughout their lifecycle. However, it does not prevent supply chain compromises from occurring during the acquisition phase. Asset tracking is more about post-acquisition management rather than the initial procurement process.

Conclusion

The acquisition process is the most critical area to review first to limit the risk of supply chain compromise for new servers. By ensuring that the procurement methods are secure, the company can effectively mitigate risks associated with potentially vulnerable or compromised equipment. The other options, while important in their own right, do not address the initial sourcing and vendor evaluation that is necessary to protect the organization from supply chain threats.