712-50 Question 429
Select 2A global company is procuring a cloud-based security monitoring service to support several business units in North America and the EU. The internal client wants rapid deployment, the security engineering team wants deep telemetry integration, privacy professionals are concerned about personal data in logs, legal counsel is reviewing cross-border data transfer terms, and procurement wants to select the lowest-cost qualified bidder. As the CISO, which TWO actions should you take FIRST to improve the likelihood of a secure, compliant, and business-aligned procurement outcome?
- A
Establish a cross-functional set of mandatory requirements and evaluation criteria, including security, privacy, legal, technical integration, service levels, and data residency needs, before vendor selection proceeds
- B
Allow procurement to down-select vendors based primarily on price first, then ask security, privacy, and legal teams to validate the preferred vendor afterward to avoid delays
- C
Require a structured due diligence process for shortlisted vendors, including review of independent assurance reports, contractual security/privacy terms, and the provider's ability to meet logging, access control, and incident notification requirements
- D
Defer privacy and legal review until after contract signature because the service is a security tool rather than a customer-facing business application
- E
Permit each stakeholder group to negotiate directly with suppliers independently so that specialized issues can be resolved faster without central coordination
Show answer and explanation
Correct answers: A, C
Explanation
The best answer is to first create a coordinated, cross-functional requirements framework and then perform structured due diligence against those requirements. This reflects mature procurement governance and aligns with common best practices in security leadership, third-party risk management, and privacy-by-design. In real organizations, successful procurement of IT security products and services depends on early involvement of business owners, security engineers, privacy professionals, legal counsel, procurement, and sometimes enterprise architecture and operations. The CISO's role is not to select tools in isolation, but to ensure the process balances business need, risk tolerance, regulatory obligations, technical fit, and commercial terms.
Relevant best practices include establishing mandatory and weighted requirements before issuing or evaluating an RFP/RFQ; involving privacy and legal stakeholders early where personal data, cross-border transfers, or processor/subprocessor relationships may exist; and conducting supplier due diligence using independent assurance artifacts and contract review. Useful references include ISO/IEC 27001 and ISO/IEC 27036 for supplier relationships, SOC 2 reports for independent control assurance, and privacy obligations under laws such as the GDPR where log data may constitute personal data. Contractual review should address security obligations, incident notification timelines, audit rights where appropriate, data location/residency, retention, deletion, and use of subcontractors. Price is important, but it should be considered after vendors demonstrate that they meet baseline security, privacy, legal, and operational requirements.
- A. Correct.
Correct. Early alignment on requirements and evaluation criteria is critical in security procurement. In this scenario, multiple stakeholder concerns must be translated into clear, weighted criteria before vendor selection. This avoids choosing a solution that is inexpensive but fails on data residency, regulatory, integration, or contractual obligations. For a CISO, this is a governance and decision-quality issue: define minimum control requirements, business objectives, privacy constraints, legal terms, and operational needs up front so procurement evaluates vendors consistently.
- B. Incorrect.
Incorrect. This is a common procurement mistake. A low-cost vendor may later fail legal, privacy, or technical due diligence, creating rework, delays, and sunk cost. In security-related procurements, price should be considered only after confirming that mandatory requirements are met. A CISO should ensure that procurement is informed by risk, compliance, and operational fit, not just commercial preference.
- C. Correct.
Correct. Shortlisted vendors should undergo formal due diligence to validate their claims and assess residual risk. Independent assurance reports such as SOC 2 or ISO/IEC 27001 certification can inform confidence, but they are not substitutes for requirement-specific review. In this case, the organization must verify incident notification commitments, support for needed telemetry, access controls, subcontractor use, data processing terms, and cross-border handling capabilities. This is a core CISO responsibility when collaborating on secure procurement.
- D. Incorrect.
Incorrect. Privacy and legal review cannot be postponed simply because the service is a security tool. Security logs may contain personal data, employee data, identifiers, IP addresses, or other regulated information. Cross-border transfers, controller/processor terms, retention, and breach notification obligations may all apply. Delaying review until after contract signature can expose the organization to compliance violations and unfavorable contractual lock-in.
- E. Incorrect.
Incorrect. While specialist input is necessary, uncoordinated stakeholder engagement often leads to conflicting requirements, inconsistent messages to suppliers, and governance gaps. The CISO should promote a coordinated process with clear ownership, consolidated requirements, and controlled negotiation authority. Specialized reviews should feed into a unified procurement and risk decision, not occur as separate ad hoc negotiations.