712-50 exam dumps

712-50 practice question 437 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 437

Single answer

A newly appointed CISO is reviewing the organization's third-party procurement process after the board questioned whether recent cloud and managed service purchases are meeting security requirements. Procurement currently reports only contract cycle time and cost savings, while security reports ad hoc findings from vendor reviews. The CISO wants a reporting standard that demonstrates whether procurements are aligned with IT security policies and procedures and can be used consistently by executive leadership. Which metric and reporting approach is the MOST effective?

  1. A

    Report the percentage of procurements that completed a documented security assessment against defined policy requirements before contract approval, along with counts of approved exceptions, remediation status, and residual risk acceptance

  2. B

    Report the number of vendors purchased from preferred suppliers, because preferred suppliers are assumed to meet enterprise security expectations

  3. C

    Report the average time procurement spent negotiating security clauses, because longer negotiations indicate stronger security due diligence

  4. D

    Report the total number of security incidents involving third parties in the last year, because incidents are the clearest measure of procurement effectiveness

Show answer and explanation

Correct answer: A

Explanation

The best answer is the option that ties procurement measurement directly to policy-required security activities and governance outcomes. For CCISO-level leadership, effective procurement security reporting should use measurable, repeatable, and decision-oriented indicators such as: completion of pre-contract security assessments, compliance with mandatory control requirements, exception counts, remediation closure, and documented residual risk acceptance. These metrics are superior because they are leading and in-process indicators, not merely operational or historical data.

A sound reporting standard typically aligns with established third-party risk management and governance practices reflected in sources such as NIST SP 800-161 for supply chain risk management, NIST SP 800-53 controls related to external system services and supplier oversight, ISO/IEC 27001 and 27002 guidance on supplier relationships, and common audit expectations for evidence of risk assessment, exception management, and accountability. Executive reporting should therefore show not just procurement efficiency, but whether purchases are consistently subjected to required security review gates and whether deviations are formally managed. This gives leadership visibility into both compliance with policy and the organization's residual risk exposure.

  • A. Correct.

    This is correct because it measures direct alignment of procurement activity with established IT security policies and procedures. It also supports governance by showing whether required security reviews occurred before commitment, how many exceptions were granted, whether remediation is progressing, and whether residual risk was formally accepted. These elements create a repeatable reporting standard that is actionable for leadership and defensible for audit purposes.

  • B. Incorrect.

    This is incorrect because preferred supplier status does not by itself prove current compliance with the organization's security policies. A vendor may be commercially preferred for pricing or operational reasons but still require a formal risk assessment, contractual controls, and exception handling. This option reflects the misconception that vendor categorization can replace policy-based security evaluation.

  • C. Incorrect.

    This is incorrect because negotiation duration is not a reliable indicator of security effectiveness or policy alignment. Long negotiations can result from legal disputes, pricing issues, or operational complexity rather than better security outcomes. This metric measures process inefficiency more than control compliance and would be weak for executive reporting.

  • D. Incorrect.

    This is incorrect because incident counts are lagging indicators and do not show whether procurement followed required security procedures before onboarding a supplier. Third-party incidents may result from operational failures after contracting and can be influenced by many factors unrelated to procurement governance. While useful as a supplemental risk metric, this does not provide the primary reporting standard for procurement alignment.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam