712-50 exam dumps

712-50 practice question 439 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 439

Single answerUnderstand the IA security requirements to be included in statements of work and other appropriate procurement documents

A global manufacturer is outsourcing the operation of a cloud-based analytics platform that will process confidential engineering data and limited personal information from employees in multiple countries. The procurement team has drafted a statement of work (SOW) focused on uptime, pricing, and delivery milestones, but the CISO is concerned that the document does not adequately protect the organization if the vendor experiences a security incident or fails to meet required control objectives. Which requirement should the CISO MOST strongly insist be added to the SOW and related procurement documents to address information assurance (IA) risk before contract award?

  1. A

    A requirement for the vendor to implement defined security controls and compliance obligations, including incident notification timeframes, right-to-audit, data handling requirements, subcontractor flow-down clauses, and clear security deliverables tied to acceptance criteria

  2. B

    A requirement for the vendor to provide a general statement that it follows industry best practices for cybersecurity, with detailed controls to be discussed after deployment begins

  3. C

    A requirement for the vendor to purchase cyber insurance, with the assumption that insurance coverage will address any control weaknesses identified during the engagement

  4. D

    A requirement for the vendor to guarantee 100% service availability and waive all limitations of liability, since availability commitments are the primary security requirement for outsourced platforms

Show answer and explanation

Correct answer: A

Explanation

For CCISO-level procurement governance, the most important principle is that information assurance requirements must be embedded in statements of work, contracts, service agreements, and other procurement documents in a manner that is specific, testable, and enforceable. This includes defining the supplier's security responsibilities, required controls, compliance obligations, evidence of assurance, reporting requirements, and the customer's oversight rights. Best practice is to align these requirements to the organization's risk assessment, data classification, legal and regulatory obligations, and third-party risk management process. Common references include NIST SP 800-161 for supply chain risk management, NIST SP 800-53 control families for security and privacy requirements, ISO/IEC 27036 for supplier relationships, and ISO/IEC 27001 Annex A supplier-security concepts. In practice, strong procurement language should address topics such as access control, encryption, logging and monitoring, incident notification, vulnerability management, audit rights, data location and retention, secure destruction, business continuity, and subcontractor obligations. The correct answer reflects these core IA procurement requirements, while the other options rely on vague assurances, misplaced confidence in insurance, or an overly narrow focus on availability.

  • A. Correct.

    This is the best answer because effective IA requirements in procurement documents must be explicit, measurable, and enforceable. Security expectations should be written into the SOW, contract, and related procurement artifacts before award, not left to interpretation later. Key elements commonly required include control requirements aligned to applicable frameworks and regulations, breach/incident reporting obligations, audit and assessment rights, data classification and handling rules, requirements for encryption and access control, personnel screening where appropriate, secure disposal/return of data, obligations for subcontractors, and acceptance criteria tied to security deliverables. This approach reduces ambiguity and gives the organization contractual remedies if the supplier fails to meet security expectations.

  • B. Incorrect.

    This is incorrect because a vague commitment to 'industry best practices' is not sufficient for procurement risk management. It does not define what controls are required, how compliance will be demonstrated, what reporting timelines apply, or how the organization can verify performance. A common misconception is that broad language provides flexibility; in reality, it often creates enforceability gaps and disputes after an incident. Security requirements should be specified before the service starts, not deferred until after deployment.

  • C. Incorrect.

    This is incorrect because cyber insurance can be a useful risk transfer mechanism, but it does not replace the need to define and require appropriate security controls in the SOW. Insurance does not prevent incidents, ensure regulatory compliance, or guarantee the vendor will implement necessary safeguards. Organizations sometimes overestimate the protection insurance provides, but contractual control requirements and assurance mechanisms remain essential.

  • D. Incorrect.

    This is incorrect because availability is only one component of information assurance. Focusing primarily on uptime and liability language ignores confidentiality, integrity, incident response, auditability, privacy, and third-party risk management. In addition, demanding 100% availability is generally unrealistic and not the most effective way to address IA concerns in procurement documents. The broader misconception is treating service levels as equivalent to security requirements.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam