712-50 Question 443
Single answerThird Party Management (5 questions)A global manufacturer is preparing to outsource its customer support platform to a SaaS provider that will process customer contact details, service histories, and limited payment-related metadata. The business unit wants to sign quickly because the provider offers strong functionality and a lower price than competitors. The CISO learns that the vendor recently completed a SOC 2 Type II audit, but the contract draft contains only generic confidentiality language and no defined security reporting timelines, right-to-audit clause, or subcontractor transparency requirements. Given the CISO's responsibility for enterprise risk management and third-party governance, what is the BEST next action before approving the engagement?
- A
Approve the vendor because the SOC 2 Type II report demonstrates adequate security controls, and operational teams can address any remaining issues after onboarding
- B
Require a risk-based third-party assessment and update the contract to include security, incident notification, audit/assurance, and subcontractor management requirements before signing
- C
Reject the vendor immediately because any provider handling customer data must offer unlimited audit rights and full on-site inspection access
- D
Ask the procurement team to obtain a cyber insurance certificate from the vendor and proceed if coverage limits are consistent with company standards
Show answer and explanation
Correct answer: B
Explanation
The best answer is to perform a risk-based third-party assessment and strengthen the contract before signing. In CCISO practice, third-party management is not satisfied by collecting a single assurance artifact or relying on price and business urgency. The CISO must ensure governance over vendor selection, onboarding, contracting, monitoring, and offboarding. For a SaaS provider processing customer-related data, the organization should validate inherent risk, review control evidence, assess legal and regulatory implications, and require contractual safeguards that reflect the sensitivity of the service. Common best practices, reflected in guidance such as NIST SP 800-161 for supply chain risk management, NIST SP 800-53 control families relating to external services and supplier oversight, ISO/IEC 27001 and 27036 supplier relationship concepts, and shared-responsibility due diligence expectations in cloud environments, emphasize proportionate risk assessment, clearly defined security requirements, incident reporting obligations, and ongoing assurance. A SOC 2 Type II report is valuable, but it is one input into a broader vendor risk decision, not a standalone approval basis.
- A. Incorrect.
Incorrect. A SOC 2 Type II report is useful evidence of control design and operating effectiveness over a period, but it does not replace the organization's own risk-based due diligence. It may not address all contractual, regulatory, data handling, incident response, concentration risk, or subcontractor concerns relevant to this engagement. Approving first and addressing gaps later weakens third-party governance and can leave the organization exposed.
- B. Correct.
Correct. The CISO should ensure a risk-based assessment is performed before approval, especially when the vendor will process sensitive customer data. In addition to reviewing independent assurance artifacts such as SOC 2, the organization should align vendor controls and contract terms to its security, privacy, legal, and business continuity requirements. Key provisions typically include incident notification timelines, right-to-audit or equivalent assurance rights, subcontractor disclosure and flow-down obligations, data protection requirements, and ongoing monitoring expectations.
- C. Incorrect.
Incorrect. Immediate rejection is not the best action based solely on the current draft. While contract gaps are significant, unlimited audit rights and unrestricted on-site inspections are often impractical in modern SaaS environments and may not be necessary if equivalent assurance mechanisms exist, such as independent audits, certifications, customer reports, and negotiated review rights. A risk-based approach is more appropriate than imposing extreme requirements without considering proportionality.
- D. Incorrect.
Incorrect. Cyber insurance can be a useful risk-transfer element, but it is not a substitute for due diligence, contractual security obligations, or operational oversight. Insurance does not ensure the vendor has adequate preventive and detective controls, nor does it define how incidents, subcontractors, or audit evidence will be managed. Proceeding based mainly on insurance coverage reflects a common misconception in third-party risk management.