712-50 Question 432
Single answerDesign vendor selection process and management policyA global manufacturing company is replacing several regional software suppliers with a single cloud-based vendor for procurement and inventory management. The platform will process supplier banking details, employee approver information, and sensitive production forecasts, and it must integrate with the company's ERP across multiple jurisdictions. The CIO wants procurement to select the lowest-cost vendor within 30 days, while legal and operations want to avoid delays. As the CISO, you have been asked to help design the vendor selection process and management policy so that it is both business-aligned and defensible to regulators and auditors. Which action is the BEST way to structure the vendor selection process before contract award?
- A
Require all candidate vendors to complete the same standard security questionnaire, then select the vendor with the fewest negative responses because that provides an objective and fast comparison.
- B
Classify the service by business criticality, data sensitivity, regulatory exposure, and integration risk; then apply a risk-based due diligence process with weighted evaluation criteria involving procurement, legal, security, privacy, and the business owner before final selection.
- C
Allow procurement to choose the preferred vendor based on cost and delivery timeline, and perform a full security assessment after contract signature so implementation is not delayed.
- D
Limit security review to contract clauses such as confidentiality, breach notification, and right to audit, because technical controls can be improved later through the normal vendor relationship.
Show answer and explanation
Correct answer: B
Explanation
The best answer is the risk-based, cross-functional approach because CCISO-level governance requires vendor selection to be aligned with enterprise risk management, legal obligations, operational dependency, and business strategy rather than driven only by cost or speed. A mature vendor selection process typically includes: inherent risk classification, due diligence depth based on risk tier, weighted selection criteria, documented stakeholder roles, evidence review, and clear approval thresholds before contract award. For cloud and outsourced service providers, recognized best practices emphasize assessing security, privacy, resiliency, subcontractor use, and regulatory exposure before onboarding. This approach is consistent with commonly accepted third-party risk management principles reflected in frameworks and guidance such as NIST SP 800-161 (supply chain risk management), NIST SP 800-53 control families related to external services and supply chain, ISO/IEC 27001 and ISO/IEC 27036 for supplier relationships, and typical governance expectations in enterprise risk and audit programs. The key principle is that vendor selection should be proportionate to risk and supported by policy-defined governance, not treated as a purely procurement decision.
- A. Incorrect.
This is incorrect because a single uniform questionnaire without risk-tiering is not sufficient for defensible vendor selection. While standardized questionnaires can improve consistency, they do not by themselves address varying levels of data sensitivity, jurisdictional obligations, operational dependency, or integration risk. A vendor with fewer questionnaire findings may still be a poor choice if the evaluation does not consider inherent risk, control maturity, resilience, subcontractor risk, or legal/privacy requirements.
- B. Correct.
This is correct because an effective vendor selection process starts with inherent risk classification and cross-functional evaluation. For a cloud platform handling sensitive business and personal data across jurisdictions and integrating with core ERP processes, the CISO should establish a risk-based due diligence model that considers business criticality, data classification, privacy obligations, architectural and integration risks, resilience expectations, and concentration risk. Weighted criteria help balance security, legal, operational, financial, and commercial considerations in a transparent way. Involving procurement, legal, privacy, security, and the business owner before award is consistent with mature third-party risk management practices and creates an auditable decision trail.
- C. Incorrect.
This is incorrect because postponing meaningful security assessment until after contract execution weakens the organization's negotiating position and increases the chance of onboarding an unsuitable vendor. If significant gaps are discovered later, the company may face remediation costs, implementation delays, or contractual lock-in. This option reflects a common but risky misconception that security due diligence can be treated as a post-award activity for critical vendors.
- D. Incorrect.
This is incorrect because contract language is important but not enough. Confidentiality, breach notification, and audit rights do not compensate for weak identity management, poor encryption, inadequate logging, weak resilience, insufficient data segregation, or unmanaged fourth-party dependencies. For a high-impact cloud service, both contractual and control-level due diligence are needed before selection. Relying on future improvements after award creates avoidable risk.