712-50 exam dumps

712-50 practice question 424 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 424

Single answerIdentify different procurement strategies and understand the importance of cost-benefit analysis during procurement of an information system

A global manufacturing company must replace its legacy identity and access management (IAM) platform within 12 months to support multiple acquisitions, stricter audit requirements, and a growing remote workforce. The CIO favors the lowest upfront bid from a vendor offering a heavily customized on-premises solution. The procurement team has not yet completed a formal cost-benefit analysis. As the CISO, you are concerned that the selected approach may create long-term security and operational risk. Which action is the MOST appropriate to recommend before finalizing the procurement decision?

  1. A

    Approve the lowest-cost proposal because capital expenditure is easier to justify than recurring subscription costs, and security controls can be added after deployment.

  2. B

    Require a cost-benefit analysis comparing procurement strategies such as build, buy, and managed/cloud service options, including total cost of ownership, integration effort, security control maturity, vendor lock-in, compliance support, and lifecycle costs.

  3. C

    Select the vendor with the most security features listed in its proposal, because feature breadth is the strongest indicator of long-term value.

  4. D

    Delay the project until the company can fully standardize all acquired business units, since procurement decisions should not be made during organizational change.

Show answer and explanation

Correct answer: B

Explanation

The best answer is Option 2 because senior security leaders are expected to guide procurement decisions using business-aligned, risk-informed analysis rather than focusing only on acquisition price. In information system procurement, different strategies, such as building internally, buying a commercial solution, or consuming a managed/cloud service, have different cost, risk, and control implications. A proper cost-benefit analysis should assess not just purchase price but total cost of ownership, implementation and integration effort, staffing requirements, ongoing administration, compliance reporting support, resilience, scalability, contractual obligations, and vendor dependency. This reflects widely accepted governance and security procurement practices found in frameworks and guidance such as NIST SP 800-53 supply chain and system acquisition-related controls, NIST SP 800-161 on supply chain risk management, and ISO/IEC 27001 and 27002 guidance on supplier relationships and information security in acquisition and development. For a CCISO, the key is ensuring procurement decisions support business objectives while managing long-term security, operational, and financial risk.

  • A. Incorrect.

    This is incorrect because focusing mainly on the lowest upfront price reflects a narrow procurement view and ignores total cost of ownership (TCO), implementation complexity, maintenance, staffing, future upgrades, and residual risk. In IAM procurements, deferring security considerations until after deployment often increases cost and introduces architectural weaknesses. A CISO should ensure security and business requirements are evaluated before award, not retrofitted later.

  • B. Correct.

    This is correct because it applies sound procurement governance and aligns with executive-level decision making expected of a CCISO. A formal cost-benefit analysis should compare viable procurement strategies, such as internal development, commercial off-the-shelf purchase, and managed or cloud-delivered service. The analysis should include direct and indirect costs, expected benefits, deployment timelines, operational overhead, control effectiveness, auditability, scalability, integration requirements, contractual constraints, and exit considerations. This approach helps leadership avoid choosing a solution that appears inexpensive initially but is more costly or riskier over its lifecycle.

  • C. Incorrect.

    This is incorrect because a long list of security features does not necessarily translate into better business value, lower risk, or easier implementation. Security capability must be assessed in context: how well the platform integrates with existing infrastructure, supports regulatory obligations, reduces operational burden, and meets business timelines. Procurement decisions based only on feature checklists commonly overlook hidden costs, complexity, and implementation risk.

  • D. Incorrect.

    This is incorrect because postponing the project may increase business and security exposure, especially when the current IAM platform is legacy and the organization is under audit and integration pressure. While standardization is beneficial, procurement can and should proceed using clearly defined requirements, phased rollout planning, and risk-based evaluation. The better action is to strengthen the decision process through comparative analysis rather than halt the initiative indefinitely.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam