712-50 Question 423
Single answerUnderstand the acquisition life cycle and determine the importance of procurement by performing Business Impact AnalysisA global manufacturing company is replacing its legacy supplier management platform with a cloud-based procurement system that will be used to source critical raw materials, approve purchase orders, and onboard strategic vendors. The CISO is asked to advise the acquisition committee before contract award. A preliminary Business Impact Analysis (BIA) shows that if the platform is unavailable for more than 8 hours, production at two plants could stop within 24 hours due to delayed replenishment orders. It also shows that vendor master data integrity is essential because incorrect banking or supplier records could lead to fraudulent payments and major financial loss. Which action should the CISO recommend FIRST to ensure procurement decisions properly reflect business impact during the acquisition life cycle?
- A
Map the BIA results to security and resilience requirements in the procurement package, including recovery objectives, data integrity controls, and supplier due diligence criteria before vendor selection
- B
Select the lowest-cost vendor first, then negotiate additional security terms after implementation begins to avoid delaying the project timeline
- C
Require the procurement team to accept the vendor's standard security questionnaire as sufficient evidence because the service is cloud-based
- D
Defer security requirements until the system design phase, since the BIA only informs disaster recovery planning and not source selection
Show answer and explanation
Correct answer: A
Explanation
In the acquisition life cycle, the BIA helps leadership determine which business processes, assets, and dependencies are mission-critical and what the consequences are if confidentiality, integrity, or availability are compromised. For procurement-related systems, this means the BIA should shape requirements early, before vendor selection, so the organization can procure solutions aligned to operational tolerance and risk appetite. In this scenario, the BIA identifies two major impacts: availability risk leading to plant disruption and integrity risk leading to fraudulent payments. Those findings should be translated into procurement requirements such as resilience objectives, integrity safeguards, monitoring, access control, segregation of duties, supplier assurance evidence, and contractual obligations. This approach is consistent with widely accepted practices in business continuity and information security governance, including the use of BIA outputs to define recovery requirements and dependency priorities, as reflected in ISO 22301 business continuity guidance, NIST SP 800-34 contingency planning principles, and NIST SP 800-161 supply chain risk management concepts. From a CCISO perspective, the key leadership decision is ensuring procurement is business-driven and risk-informed at the outset of the acquisition process, rather than treating security as an afterthought.
- A. Correct.
Correct. The BIA should directly inform acquisition requirements by identifying the business consequences of downtime, integrity failure, and supplier dependency. In this scenario, the 8-hour disruption threshold and the risk of fraudulent payments should be translated into concrete procurement criteria such as RTO/RPO expectations where appropriate, availability SLAs, incident notification requirements, segregation of duties, audit logging, strong vendor master data controls, and due diligence on the provider's operational resilience. This is the most appropriate first step because it embeds business-driven security and resilience requirements before vendor selection and contract award, when they have the greatest influence on procurement outcomes.
- B. Incorrect.
Incorrect. Cost is an important procurement factor, but choosing a vendor before defining business-impact-driven security requirements creates substantial risk. Security and resilience terms are harder and more expensive to add after selection, and the organization may end up with a provider that cannot meet critical operational or integrity needs. This option reflects the common misconception that security can be bolted on later without affecting acquisition risk.
- C. Incorrect.
Incorrect. A standard questionnaire alone is not sufficient evidence for a system supporting critical procurement functions. Cloud delivery does not reduce the need for due diligence; it often increases the need for independent assurance, contractual controls, and review of security architecture, resilience capabilities, and third-party risk. This option reflects the misconception that a vendor's generic cloud status or self-attestation is enough for high-impact services.
- D. Incorrect.
Incorrect. The BIA is not limited to disaster recovery planning. It is a key input to acquisition, risk treatment, control selection, service levels, and contract requirements because it identifies what matters most to the business. Deferring security requirements until design weakens the organization's negotiating position and may result in selecting a supplier that cannot satisfy critical business and security needs.