712-50 Question 425
Single answerIdentify different procurement strategies and understand the importance of cost-benefit analysis during procurement of an information systemA global manufacturing company plans to replace its legacy identity and access management (IAM) platform across 18 countries. The CIO wants the quickest deployment and prefers selecting the vendor with the lowest upfront bid. The procurement team has narrowed the choices to: a commercial off-the-shelf (COTS) cloud IAM service with subscription pricing, a heavily customized on-premises suite requiring significant integration work, and a hybrid managed service from a systems integrator. As the CISO, you are asked to recommend the most defensible procurement approach from a security governance and business perspective. Which action should you take FIRST to support a sound procurement decision?
- A
Recommend the lowest-cost bidder because procurement policy emphasizes competitive pricing and rapid acquisition
- B
Perform a cost-benefit analysis comparing procurement strategies using total cost of ownership, security control coverage, integration effort, compliance obligations, and vendor risk over the system lifecycle
- C
Select the most security-feature-rich option immediately because stronger controls will offset any operational or financial concerns
- D
Delay the decision until the internal security architecture team can build a custom IAM platform that precisely matches business requirements
Show answer and explanation
Correct answer: B
Explanation
The best answer is to perform a cost-benefit analysis across the available procurement strategies before making a recommendation. At the CCISO level, procurement decisions must balance security, cost, operational sustainability, legal and regulatory requirements, and business outcomes. For an information system such as IAM, this means comparing options such as COTS/SaaS procurement, customized on-premises acquisition, and managed services using lifecycle-oriented criteria rather than upfront price or feature count alone. Best practices from governance and risk frameworks support this approach: NIST guidance on system acquisition and supply chain risk emphasizes incorporating security requirements, third-party considerations, and lifecycle planning into procurement; ISO/IEC 27001 and ISO/IEC 27036 stress supplier relationship and information security in vendor engagements; and standard business-case practice supports evaluating total cost of ownership and expected benefits before approval. A mature procurement recommendation should therefore be risk-adjusted, evidence-based, and aligned to enterprise strategy.
- A. Incorrect.
This is incorrect because focusing primarily on the lowest upfront bid is a common procurement mistake. In information system acquisition, the cheapest initial price may produce higher long-term costs through integration complexity, control gaps, vendor lock-in, operational overhead, audit remediation, and contract management. CCISO-level decision-making requires aligning procurement with enterprise risk, business objectives, and lifecycle cost rather than purchase price alone.
- B. Correct.
This is correct because the first defensible step is to conduct a structured cost-benefit analysis across the viable procurement strategies. For an IAM platform, this should include total cost of ownership (licensing, implementation, migration, integration, staffing, training, support, and exit costs), expected security outcomes, regulatory and data residency implications, third-party risk, resilience, and business enablement. This approach allows leadership to compare COTS cloud, customized on-premises, and managed-service models on both financial and risk-adjusted grounds, which is consistent with executive security governance responsibilities.
- C. Incorrect.
This is incorrect because selecting the option with the most features without evaluating fit-for-purpose, integration feasibility, operating model, and cost effectiveness is not sound executive procurement practice. More features do not necessarily translate to better security outcomes if the organization cannot properly implement, govern, or sustain them. This option reflects the misconception that maximum technical capability automatically equals best enterprise value.
- D. Incorrect.
This is incorrect because building a custom platform should not be the default response, especially when viable procurement alternatives already exist. Custom development typically introduces higher delivery risk, longer timelines, increased maintenance burden, specialized staffing requirements, and greater long-term cost. While custom solutions may occasionally be justified, a CISO should first evaluate available procurement strategies through business and risk analysis before endorsing a build option.