712-50 Question 428
Single answerA global company plans to procure a cloud-based security analytics platform that will ingest endpoint, identity, and network telemetry from multiple regions, including the EU. The internal client wants rapid deployment to improve detection capability before a major product launch. Legal counsel is concerned about cross-border data transfers and liability terms, while privacy professionals have raised questions about personal data contained in logs. Security engineers want to validate integration with existing controls and logging standards. As the CISO overseeing the procurement, which action should you take FIRST to best align stakeholders and reduce the risk of selecting an unsuitable solution?
- A
Direct procurement to choose the lowest-cost vendor that meets the stated functional requirements, then allow legal and privacy teams to negotiate contract changes after selection
- B
Establish a cross-functional evaluation process with defined security, privacy, legal, operational, and business requirements, and require vendors to be assessed against these criteria before down-selection
- C
Ask the security engineering team to run a proof of concept immediately, since technical validation is the most objective way to resolve stakeholder disagreements
- D
Have legal counsel draft stricter contract language first, because contractual protection is the primary control for cloud security procurement
Show answer and explanation
Correct answer: B
Explanation
In CCISO-level practice, procurement of IT security products and services is a governance and risk management activity, not merely a technical or purchasing exercise. The CISO should first establish a cross-functional decision framework that incorporates the internal client's business objectives, legal obligations, privacy requirements, technical architecture, security operations needs, supplier risk, and commercial constraints. For a cloud-based analytics platform handling telemetry from multiple jurisdictions, the organization should define evaluation criteria covering data classification, data residency, international transfer mechanisms, access controls, logging and retention requirements, incident notification, integration capability, service levels, auditability, and contractual risk allocation. This approach aligns with widely used best practices such as NIST SP 800-161 for supply chain risk management, NIST SP 800-53 controls related to external services and privacy, ISO/IEC 27001 and 27036 principles for supplier relationships, and privacy-by-design expectations reflected in regulations such as the GDPR. A proof of concept and contract negotiation are important later steps, but they should be driven by agreed cross-functional requirements rather than used as substitutes for stakeholder alignment.
- A. Incorrect.
Incorrect. Cost and basic functionality alone are insufficient for security product procurement, especially where regulated or sensitive telemetry may include personal data and cross-border transfers. Delaying legal and privacy review until after vendor selection creates rework, negotiation deadlock, or the need to restart procurement if the chosen vendor cannot meet required terms. This option reflects a common mistake: treating security procurement like a standard commodity purchase rather than a risk-based, stakeholder-driven decision.
- B. Correct.
Correct. The most effective first step is to create a structured, cross-functional evaluation process that aligns business, security, privacy, legal, and operational requirements before narrowing vendors. This ensures the organization evaluates issues such as data residency, controller/processor responsibilities, breach notification obligations, integration requirements, logging formats, retention, support models, and liability terms in a coordinated way. It also supports defensible procurement decisions and reduces the chance of selecting a technically strong product that fails legal, privacy, or operational requirements.
- C. Incorrect.
Incorrect. A proof of concept can be valuable, but it should occur after core evaluation criteria are agreed upon. Otherwise, the organization risks spending time validating a solution that later proves unacceptable due to privacy, contractual, jurisdictional, or operational constraints. This option represents the misconception that technical fit should precede governance and risk requirements in security procurement.
- D. Incorrect.
Incorrect. Contractual terms are important, but they are not the sole or primary starting point for procurement decisions. A vendor may agree to some legal language yet still fail to meet technical, architectural, privacy, or business needs. Starting only with legal terms can also miss whether the service can integrate with existing controls, meet monitoring objectives, or support the required operating model. Effective procurement requires coordinated input across stakeholders, not a contract-only approach.