712-50 Question 242
Single answerIdentify, negotiate and manage vendor agreement and communityA global manufacturer is negotiating a five-year agreement with a cloud-based managed detection and response (MDR) provider that will monitor logs containing sensitive operational and employee data from multiple countries. The procurement team wants to finalize the contract quickly because of recent ransomware incidents. As the newly appointed CCISO, you are asked to identify the most effective contractual control to reduce third-party security and compliance risk while preserving the company's ability to govern the vendor over the life of the agreement. Which action should you prioritize during negotiation?
- A
Require the vendor to sign a broad confidentiality agreement and rely on annual sales presentations for assurance of security maturity
- B
Include detailed security requirements in the master service agreement, including right-to-audit, breach notification timeframes, data location and subprocessor disclosure, measurable service levels, and obligations to support regulatory compliance
- C
Accept the vendor's standard contract if the provider can demonstrate strong market reputation and a large customer base in the manufacturing sector
- D
Shift all cybersecurity responsibility to the vendor through indemnification language so internal governance reviews are no longer necessary
Show answer and explanation
Correct answer: B
Explanation
In CCISO practice, vendor agreement negotiation is not just a procurement activity; it is a risk treatment and governance function. The best answer is to embed security, privacy, operational resilience, and oversight requirements directly into the contract so they are enforceable throughout the vendor lifecycle. For a provider handling sensitive data across borders, the agreement should address items such as right-to-audit or equivalent assurance mechanisms, incident notification timelines, data handling and residency, subprocessor approval or disclosure, evidence of control effectiveness, business continuity expectations, termination and data return/destruction provisions, and compliance support responsibilities. This reflects widely accepted third-party risk management principles found in frameworks and guidance such as NIST SP 800-161 for cyber supply chain risk management, NIST SP 800-53 control families related to external service providers, ISO/IEC 27036 for supplier relationships, and ISO/IEC 27001 Annex A guidance on supplier security. From a CCISO perspective, the key is to negotiate terms that enable ongoing governance of the vendor community rather than treating contract signature as the end of risk management.
- A. Incorrect.
This is insufficient. A confidentiality agreement is only one narrow legal safeguard and does not establish operational security obligations, performance metrics, oversight rights, or compliance support. Relying on vendor presentations is a common mistake because marketing materials are not a substitute for enforceable contract terms, due diligence evidence, or ongoing governance.
- B. Correct.
This is correct. For a high-risk vendor handling sensitive data across jurisdictions, the CCISO should negotiate specific, enforceable provisions in the agreement. These should typically include security control expectations, audit and assessment rights, incident and breach notification requirements, data residency and transfer terms, subprocessor transparency, service-level metrics, remediation obligations, evidence of independent assurance, and responsibilities for supporting legal and regulatory requirements. This approach aligns with mature third-party risk management and vendor governance practices.
- C. Incorrect.
This is incorrect. Reputation and market share may inform due diligence, but they do not replace contractual risk treatment. A well-known provider can still fail to meet the organization's control, privacy, resilience, or reporting expectations. A CCISO should avoid assuming that popularity or industry presence provides adequate assurance without binding terms and governance mechanisms.
- D. Incorrect.
This is incorrect. Indemnification can help allocate some financial risk, but it does not transfer accountability for governance, regulatory obligations, or business risk ownership. The organization remains responsible for overseeing vendors that process its data or support critical services. This option reflects a common misconception that legal risk transfer eliminates the need for ongoing third-party risk management.