712-50 Question 243
Single answerIdentify, negotiate and manage vendor agreement and communityA global financial services company plans to outsource a customer analytics platform to a third-party SaaS provider. The platform will process regulated customer data and integrate with several internal systems. During contract negotiations, the vendor offers a strong uptime SLA and competitive pricing, but resists adding detailed security and audit provisions, arguing that its standard contract is used by all customers. As the CISO, you must reduce third-party risk while enabling the business to move forward on schedule. Which action is the MOST appropriate to prioritize during negotiation?
- A
Accept the vendor's standard contract because the uptime SLA and market reputation indicate adequate operational maturity
- B
Require a risk-based addendum covering security obligations, right to audit or equivalent assurance, incident notification timelines, data handling requirements, and subcontractor controls before signing
- C
Defer all security requirements until after implementation and manage them through informal governance meetings with the vendor
- D
Rely on the vendor's sales commitment that it follows industry best practices, since regulated data is encrypted in transit
Show answer and explanation
Correct answer: B
Explanation
In CCISO practice, vendor agreement negotiation is a core control point for managing third-party risk before services begin. The most effective action is to establish a contract structure that translates security requirements into enforceable obligations. For high-impact or regulated services, this typically includes a security addendum or equivalent terms addressing control requirements, audit rights or acceptable third-party attestations, breach and incident notification timelines, data ownership, data retention and destruction, subcontractor oversight, compliance obligations, and exit support. This aligns with widely accepted practices from NIST SP 800-161 on supply chain risk management, NIST SP 800-53 controls such as SA-9 for external system services, and ISO/IEC 27036 guidance on supplier relationships. It also supports principles reflected in ISO/IEC 27001 Annex A supplier relationship controls. The key leadership decision is not to block the business unnecessarily, but to ensure residual risk is understood, contractually bounded, and managed through both due diligence and ongoing vendor governance.
- A. Incorrect.
This is incorrect because availability commitments and brand reputation do not adequately address information security, privacy, compliance, or legal accountability. A vendor may deliver good uptime yet still expose the organization to unacceptable risks related to breach notification, data residency, subcontractor usage, auditability, or control assurance. A common misconception is that operational reliability is a proxy for security governance; in third-party risk management, those are related but distinct concerns.
- B. Correct.
This is correct because the CISO should prioritize enforceable, risk-based contractual terms that align the vendor's obligations with the organization's regulatory, legal, and security requirements. For a SaaS provider handling regulated data, the agreement should clearly define minimum security controls, evidence of control effectiveness, incident notification timeframes, rights to audit or accepted independent assurance mechanisms, data classification and handling expectations, return and destruction requirements, and restrictions or transparency around subcontractors. This approach balances business enablement with accountable risk treatment and is consistent with mature third-party risk management practices.
- C. Incorrect.
This is incorrect because security expectations that are not contractually documented are difficult to enforce later, especially once switching costs and business dependence increase. Informal governance meetings can support ongoing vendor management, but they are not a substitute for binding terms in the master agreement, data processing terms, or security addendum. Choosing this option reflects the common error of treating vendor risk management as an operational activity only, rather than a lifecycle discipline beginning at procurement and contract negotiation.
- D. Incorrect.
This is incorrect because sales statements are not enforceable security commitments and encryption in transit addresses only a narrow portion of the risk. It does not cover access control, logging, incident response, data retention, privileged administration, segregation of customer environments, or downstream subcontractor risk. Candidates might choose this because encryption is important, but relying on a single technical control and non-contractual assurances is not sufficient for regulated processing arrangements.