712-50 exam dumps

712-50 practice question 391 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 391

Single answerDomain 5: Strategic Planning, Finance, Procurement, and Third-Party Management (11%)

A global manufacturing company is replacing several regional collaboration tools with a single cloud-based SaaS platform. Procurement wants to award the contract quickly because the selected vendor offers a significant discount if signed before quarter-end. The vendor has completed a standard security questionnaire and provided a SOC 2 Type II report, but your security team identified two material gaps: the contract does not clearly define breach notification timeframes, and the vendor reserves the right to use subprocessors without prior customer approval. The business owner argues these issues can be handled after onboarding because the tool is not considered mission-critical. As the CCISO, what is the MOST appropriate action to balance business objectives with third-party risk management?

  1. A

    Approve the procurement because a SOC 2 Type II report provides sufficient assurance, then address contract language during the first annual vendor review.

  2. B

    Require procurement to delay signature until security and legal negotiate minimum contractual controls for incident notification and subprocessor governance, while documenting any residual risk for executive approval if exceptions remain.

  3. C

    Reject the vendor entirely and require the business to select an on-premises alternative because cloud providers create unacceptable third-party risk.

  4. D

    Allow the business owner to accept the risk directly since the application is not mission-critical and falls outside enterprise third-party governance.

Show answer and explanation

Correct answer: B

Explanation

The best answer is Option 2 because mature third-party risk management requires both assurance evidence and enforceable contractual controls before service adoption. In practice, a SOC 2 Type II report helps validate that a vendor operates controls over time, but it does not guarantee that the vendor's obligations meet your organization's legal, regulatory, operational, and incident response requirements. Two red flags in the scenario are especially significant: undefined breach notification timing and unrestricted subprocessor use. Breach notification clauses are critical for meeting regulatory deadlines, contractual obligations to customers, and internal incident response needs. Subprocessor governance matters because downstream providers can materially change the vendor's risk profile, data residency, and compliance posture.

From a CCISO perspective, the correct approach is not to block the business reflexively, nor to wave the risk through for the sake of speed. Instead, the CCISO should ensure that procurement, legal, and security negotiate minimum acceptable terms aligned to policy and risk appetite. If some issues remain unresolved but the business case is compelling, the remaining exposure should be explicitly documented as residual risk and approved through the enterprise's formal exception or risk acceptance process.

This approach aligns with common best practices reflected in third-party risk management guidance and control frameworks, such as NIST SP 800-161 for supply chain risk management, NIST SP 800-53 controls related to external service providers and incident handling, ISO/IEC 27036 on supplier relationships, and ISO/IEC 27001 Annex A controls concerning supplier security and information security in supplier agreements. These sources consistently emphasize pre-contract due diligence, defined security requirements in agreements, and formal governance for exceptions and residual risk.

  • A. Incorrect.

    Incorrect. A SOC 2 Type II report is valuable evidence of control design and operating effectiveness over a defined period, but it does not replace organization-specific contractual requirements. Breach notification obligations and subprocessor governance are legal and risk allocation issues that must be addressed before onboarding when possible. Deferring them to an annual review leaves the organization exposed during the highest-risk period: immediately after adoption.

  • B. Correct.

    Correct. This is the most appropriate risk-based and governance-aligned response. In third-party management, due diligence is not limited to reviewing assurance reports; it also includes ensuring the contract contains security, incident notification, audit, data handling, and subcontractor/subprocessor provisions that align with enterprise risk appetite. If the business still wants to proceed despite unresolved issues, the residual risk should be formally documented and escalated to the appropriate executive risk owner, not handled informally. This balances speed, accountability, and prudent control over vendor risk.

  • C. Incorrect.

    Incorrect. Rejecting the vendor solely because it is cloud-based is not a risk-based decision and does not reflect sound strategic planning or procurement practice. CCISO-level leadership should enable the business through appropriate due diligence, contractual safeguards, and exception handling rather than impose blanket prohibitions. Cloud services can be acceptable when risks are properly evaluated and managed.

  • D. Incorrect.

    Incorrect. Business input is important, but third-party risk governance cannot be bypassed because a service is perceived as less critical. Many so-called non-mission-critical SaaS tools still process sensitive data, create regulatory exposure, or introduce supply-chain risk. Risk acceptance must follow the organization's governance model and approval authority, typically involving the designated risk owner and often legal, procurement, and security stakeholders.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam