712-50 exam dumps

712-50 practice question 442 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 442

Single answerThird Party Management (5 questions)

A global manufacturing company is outsourcing payroll processing to a cloud-based third party. The provider will store employee personal data, bank account information, and tax identifiers for multiple countries. The board has approved the business case and wants the service live within 60 days. As the CCISO, you determine that the vendor's sales team has provided a SOC 2 report and a standard contract, but there is no evidence of data residency commitments, breach notification timelines, or subcontractor transparency. Which action should you take FIRST to best reduce organizational risk while still supporting the business timeline?

  1. A

    Approve the engagement because the SOC 2 report demonstrates that the provider's controls are adequate for handling sensitive payroll data

  2. B

    Require a risk-based third-party assessment focused on legal, regulatory, data handling, and contractual gaps before finalizing onboarding

  3. C

    Delay the project until the provider agrees to a full onsite audit of all its facilities and all downstream service providers

  4. D

    Transfer accountability for the risk decision to the HR business owner since payroll is the data owner and service sponsor

Show answer and explanation

Correct answer: B

Explanation

The best answer is to require a risk-based third-party assessment before finalizing onboarding. In third-party management, the key principle is that due diligence and contractual controls should be aligned to the inherent risk of the service, the sensitivity of the data involved, regulatory exposure, and business criticality. In this scenario, payroll processing involves highly sensitive personal and financial information, likely triggering privacy, data protection, and cross-border transfer obligations. The vendor's SOC 2 report is helpful but incomplete because it does not necessarily address organization-specific requirements such as data residency, notification timeframes, right-to-audit, subprocessors, data retention, and jurisdictional compliance.

Best practices from third-party risk management programs, as reflected in frameworks such as NIST SP 800-161 for cyber supply chain risk management, NIST SP 800-53 controls related to external service providers, ISO/IEC 27036 for supplier relationships, and ISO/IEC 27001 Annex A supplier controls, emphasize performing risk-based due diligence before onboarding and ensuring contractual clauses address security, privacy, incident reporting, and subcontractor oversight. From a CCISO perspective, the priority is to enable the business safely by identifying and treating risk through proportionate assessment and contract negotiation, rather than either rubber-stamping the vendor based on generic attestations or imposing unnecessarily disruptive assurance demands.

  • A. Incorrect.

    This is incorrect. A SOC 2 report can provide useful assurance over selected controls, but it is not sufficient by itself to approve a high-risk third-party engagement involving sensitive personal data across jurisdictions. It may not address data residency, privacy law obligations, subcontractor use, incident notification requirements, or specific contractual responsibilities needed by the organization. Relying only on the existence of an assurance report is a common mistake in third-party risk management.

  • B. Correct.

    This is correct. A risk-based third-party assessment is the most appropriate first step because the scenario already identifies material gaps in areas critical to payroll outsourcing: cross-border data handling, privacy and regulatory compliance, breach notification, and fourth-party transparency. The CCISO should drive due diligence proportionate to the inherent risk of the service and ensure contract provisions address identified gaps before onboarding. This approach supports the business timeline better than demanding maximum assurance activities that may not be necessary.

  • C. Incorrect.

    This is incorrect. An onsite audit of all facilities and downstream providers is not usually the first or most practical action, especially with a 60-day deadline. While onsite reviews may be justified for certain critical vendors, mature third-party risk programs apply assurance methods proportionate to risk. In many cases, contractual controls, targeted due diligence, independent reports, and evidence reviews can address immediate concerns more efficiently than insisting on the most burdensome option.

  • D. Incorrect.

    This is incorrect. Business owners and data owners share responsibility in vendor decisions, but accountability for third-party cyber risk governance cannot simply be transferred away from security leadership. The CCISO is expected to provide risk oversight, advise on control requirements, and ensure due diligence is performed. Delegating the decision without addressing the identified gaps would weaken governance and leave the organization exposed.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam