712-50 Question 436
Single answerA newly appointed CISO is asked to improve board reporting on third-party technology procurements after an audit found that several cloud and SaaS purchases were approved without consistent security review. Procurement, legal, and IT each maintain separate tracking methods, and business units complain that security requirements delay contracting. The CISO wants a reporting standard that demonstrates whether procurement activity is aligned with security policy while also helping executives identify process bottlenecks. Which metric and reporting approach is MOST appropriate to implement first?
- A
Report the total number of vendors onboarded each quarter and highlight business units with the highest purchasing volume
- B
Report the percentage of procurements that completed required security review before contract signature, segmented by vendor risk tier and including average cycle time to disposition exceptions
- C
Report the number of security clauses inserted into contracts and the total legal review hours spent negotiating them
- D
Report the number of vendors that experienced security incidents in the last 12 months, regardless of whether they were assessed before procurement
Show answer and explanation
Correct answer: B
Explanation
The best initial reporting standard is one that ties procurement activity to required security governance checkpoints and provides decision-useful insight to executives. In this scenario, the key objective is to measure whether procurements are aligned with IT security policies and procedures, not merely to count contracts, clauses, or incidents. Therefore, the strongest metric is the percentage of procurements completing required security review before contract signature, with segmentation by vendor risk tier and supporting cycle-time data.
This approach reflects common best practices in third-party risk management and security governance: define mandatory control points, measure compliance to those control points, stratify reporting by inherent risk, and include process efficiency indicators to identify bottlenecks. It also supports effective exception management by showing how long risk decisions take rather than allowing informal workarounds.
Relevant good practices can be found across established frameworks and guidance, including NIST SP 800-161 for supply chain risk management, NIST SP 800-53 controls related to external service providers and assessments, ISO/IEC 27001 and 27036 guidance on supplier relationships, and general governance principles from COBIT emphasizing measurable control objectives and management reporting. At the CCISO level, the focus is on selecting metrics that are actionable, risk-based, and aligned to policy compliance and executive oversight.
- A. Incorrect.
Incorrect. Procurement volume is an operational sourcing metric, but by itself it does not measure alignment with IT security policies and procedures. It also does not show whether required reviews occurred, whether high-risk procurements were handled appropriately, or whether delays are caused by security governance or by other parts of the process.
- B. Correct.
Correct. This metric directly measures adherence to procurement security policy by testing whether required security review occurred before contract execution. Segmenting by vendor risk tier makes the reporting meaningful because higher-risk suppliers should receive stronger scrutiny. Including average cycle time for reviews and exception disposition helps leadership balance compliance and business agility, which is essential in executive reporting. This approach supports governance by showing both control effectiveness and process efficiency.
- C. Incorrect.
Incorrect. Contract clause counts and legal effort are not reliable indicators of procurement alignment with security policy. A high number of clauses may reflect contract complexity rather than better risk management, and legal hours measure effort, not control outcomes. This is a common mistake when organizations report activity rather than policy compliance and risk reduction.
- D. Incorrect.
Incorrect. Vendor security incidents are relevant to third-party risk management, but this is a lagging indicator and does not specifically measure whether procurement controls were followed. It also mixes assessed and unassessed vendors, which weakens its usefulness as a governance metric for procurement process compliance.