712-50 Question 433
Single answerDesign vendor selection process and management policyA newly appointed CISO is formalizing the organization's vendor selection process and third-party management policy after an incident involving a cloud service provider that was onboarded quickly by a business unit without adequate due diligence. The board has asked for a process that reduces third-party risk without unnecessarily delaying procurement. Which action should the CISO implement FIRST to best align vendor onboarding with business impact and security governance?
- A
Require every vendor to complete the same comprehensive security assessment and obtain CISO approval before any contract is signed
- B
Establish a risk-tiering model that classifies vendors by data sensitivity, connectivity, criticality, and regulatory impact, and then applies due diligence and approval requirements based on tier
- C
Delegate vendor security reviews to the procurement department, since they already manage contracts and supplier relationships
- D
Approve vendors based primarily on possession of industry certifications such as ISO 27001 or SOC 2, since these demonstrate adequate security controls
Show answer and explanation
Correct answer: B
Explanation
The best first step in designing a vendor selection process and management policy is to create a risk-based segmentation model for third parties. This allows the organization to align due diligence depth, approval workflows, security requirements, contract provisions, and ongoing monitoring with actual business and cyber risk. In practice, common criteria include whether the vendor processes sensitive data, has privileged or network access, supports critical operations, uses subcontractors, or creates jurisdictional or regulatory exposure. This approach is consistent with established third-party risk management practices reflected in frameworks and guidance such as NIST SP 800-161 on cyber supply chain risk management, NIST SP 800-53 control families related to external service providers, and ISO/IEC 27036 guidance on supplier relationships. A CCISO should ensure procurement, legal, privacy, compliance, and business stakeholders participate, but the policy should be driven by enterprise risk management principles rather than uniform reviews or certification-only shortcuts.
- A. Incorrect.
This is not the best first action because applying the same depth of review to every vendor is inefficient and can create unnecessary procurement bottlenecks. While high-risk vendors may require comprehensive assessment and executive approval, low-risk vendors should typically follow streamlined due diligence. A mature third-party risk management program is risk-based rather than one-size-fits-all.
- B. Correct.
This is correct because a risk-tiering model is the foundation of an effective vendor selection and management policy. Classifying vendors by factors such as the type of data handled, level of network access, service criticality, and applicable legal or regulatory obligations allows the organization to tailor security reviews, contract clauses, ongoing monitoring, and approval authority appropriately. This approach supports governance while preserving business agility.
- C. Incorrect.
This is incorrect because procurement is an important stakeholder but should not independently own security risk decisions. Vendor security assessments require input from information security, legal, privacy, compliance, and business owners. Delegating the security review function solely to procurement creates a governance gap and increases the likelihood that material cyber risks will be overlooked.
- D. Incorrect.
This is incorrect because certifications and attestation reports can be useful inputs, but they are not sufficient on their own for vendor approval. They may not cover the specific services in scope, may be outdated, or may not address the organization's unique risk exposure, contractual requirements, data flows, or integration methods. Overreliance on certifications is a common mistake in third-party risk management.