712-50 exam dumps

712-50 practice question 422 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 422

Single answerUnderstand the acquisition life cycle and determine the importance of procurement by performing Business Impact Analysis

A global manufacturer is replacing its legacy customer order management platform with a cloud-based SaaS solution. The procurement committee wants to award the contract primarily to the lowest-cost vendor because all shortlisted vendors appear to meet functional requirements. As the CISO, you review the Business Impact Analysis (BIA) and find that an outage of more than 4 hours during peak season would halt order processing across multiple regions, trigger contractual penalties, and disrupt downstream warehouse and shipping operations. Which action should you recommend FIRST to ensure procurement decisions properly reflect business impact across the acquisition life cycle?

  1. A

    Require procurement to incorporate the BIA-derived recovery time, recovery point, service dependency, and supplier resilience requirements into the vendor evaluation and contracting criteria before selecting a vendor

  2. B

    Select the lowest-cost vendor now and plan to negotiate stronger security and availability terms during implementation after the contract is signed

  3. C

    Ask the business units to accept the outage risk formally because peak-season disruptions are already identified in the BIA

  4. D

    Defer the procurement decision until the security team completes a full penetration test against each shortlisted SaaS vendor environment

Show answer and explanation

Correct answer: A

Explanation

The best answer is to require procurement to use the BIA as a decision input during acquisition planning and vendor evaluation. In the acquisition life cycle, the organization should define business, security, continuity, and resilience requirements before supplier selection, then validate them during due diligence and enforce them in the contract and SLA. A BIA identifies critical processes, dependencies, maximum tolerable downtime, financial and operational impacts, and recovery objectives. Those outputs should shape procurement requirements such as uptime commitments, support windows, geographic resilience, backup and recovery expectations, subcontractor transparency, incident notification, audit rights, and exit provisions. This aligns with widely accepted practices in business continuity and third-party risk management, including guidance from NIST SP 800-34 on contingency planning and NIST SP 800-161 on supply chain risk management, as well as ISO 22301 principles for business continuity. For a CCISO, the key leadership decision is ensuring procurement is risk-informed and business-driven, rather than cost-driven in isolation.

  • A. Correct.

    Correct. A BIA is intended to translate business disruption consequences into recovery and resiliency requirements, such as RTO, RPO, dependency mapping, and critical service expectations. In procurement, these outputs should directly influence vendor selection criteria, due diligence, contract clauses, and service level requirements. For a mission-critical platform, choosing a supplier without aligning procurement to BIA findings can create a mismatch between business tolerance for downtime and the supplier's actual capabilities.

  • B. Incorrect.

    Incorrect. This is a common procurement mistake. Once a vendor is selected, the organization's leverage to impose meaningful resilience, service level, audit, and incident notification terms is reduced. Availability, recovery, support coverage, and dependency requirements should be established before award as part of acquisition planning and source selection, not deferred until implementation.

  • C. Incorrect.

    Incorrect. Risk acceptance is not the first or best response when the BIA shows material operational and contractual impact. The purpose of the BIA is to inform control, recovery, and sourcing requirements so the organization can reduce risk to an acceptable level. Formal acceptance may be appropriate only after evaluating feasible treatment options and obtaining proper executive approval, not as a substitute for integrating BIA results into procurement.

  • D. Incorrect.

    Incorrect. Penetration testing may be useful in some contexts, but it is not the first procurement action and is often not feasible or contractually permitted against a SaaS provider's production environment. More importantly, the core issue here is acquisition governance: the vendor selection process must be driven by business impact and resilience requirements identified in the BIA. Due diligence should include assurance evidence, certifications, audit reports, architecture reviews, and contractual controls, not rely solely on pen testing.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam