712-50 exam dumps

712-50 practice question 444 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 444

Single answerDesign third party selection process

A global manufacturing company is selecting a managed security services provider (MSSP) to monitor its hybrid environment, which includes OT-connected plants, cloud workloads, and a 24/7 SOC. The procurement team wants to award the contract primarily based on cost and a vendor's claim of broad security coverage. As the CISO, you are asked to design the third-party selection process so that it reduces risk and supports defensible decision-making. Which action should you take FIRST to establish an effective vendor selection process?

  1. A

    Require all bidders to submit their latest SOC 2 report and select the vendor with the fewest exceptions

  2. B

    Define risk-based evaluation criteria tied to business requirements, data sensitivity, regulatory obligations, and critical service outcomes before reviewing vendor proposals

  3. C

    Shortlist only vendors already used by peer companies in the same industry to reduce implementation uncertainty

  4. D

    Ask procurement to negotiate the strongest indemnification clauses first, since contractual protection is the primary control for third-party risk

  5. E

    Select the vendor with the most security tools in its service stack because broader tooling generally provides stronger coverage

Show answer and explanation

Correct answer: B

Explanation

In CCISO practice, designing a third-party selection process begins with business-aligned, risk-based requirements rather than vendor marketing, industry popularity, or contract terms in isolation. The CISO should establish evaluation criteria before reviewing proposals so the organization can compare vendors against consistent factors such as service criticality, data classification, regulatory obligations, operational resilience, incident response capability, architecture fit, geographic and jurisdictional issues, subcontractor use, and concentration risk. This reflects common third-party risk management practices found in NIST SP 800-161 for supply chain risk management, NIST SP 800-53 control families related to external service providers, ISO/IEC 27036 guidance on supplier relationships, and broader governance principles in ISO/IEC 27001 and 27002. Assurance artifacts like SOC 2 reports, penetration test summaries, certifications, and contractual clauses are important inputs, but they should be evaluated within a predefined selection framework based on the organization's specific risk profile and business needs.

  • A. Incorrect.

    This is a useful due diligence input, but it is not the first step in designing the selection process. A SOC 2 report provides assurance information about controls at a point in time or over a review period, but it does not by itself determine whether the vendor meets the organization's specific business, operational, regulatory, and resilience requirements. Choosing based mainly on report exceptions can cause the organization to overlook service fit, OT capability, incident response expectations, data handling requirements, and concentration risk.

  • B. Correct.

    This is correct because an effective third-party selection process starts with internally defined, risk-based criteria aligned to the service being procured. For an MSSP supporting hybrid and OT-connected operations, the organization should first identify business objectives, crown-jewel assets, required outcomes, legal and regulatory requirements, data access expectations, service-level needs, integration requirements, geographic constraints, and risk tolerance. These criteria then drive the RFP, weighting model, due diligence, and final selection in a way that is auditable and defensible.

  • C. Incorrect.

    Peer usage can be informative, but it is not a sound first step. This approach can introduce herd mentality and may ignore the company's unique operating environment, especially the OT component and specific risk appetite. A vendor that works well for a peer may still be unsuitable due to different architectures, compliance obligations, or response requirements.

  • D. Incorrect.

    Contractual protections matter, but they are not the primary control and should not come first. Indemnification, liability caps, audit rights, and security addenda are important risk treatment mechanisms after the organization understands what risks matter most and which service requirements are essential. A weak vendor cannot be made acceptable solely through contract language, particularly for high-impact operational services.

  • E. Incorrect.

    This is incorrect because more tools do not necessarily translate to better risk reduction or service quality. Tool sprawl can create integration complexity, weak accountability, or unnecessary cost. The selection process should focus on the vendor's ability to meet defined operational outcomes, governance expectations, detection and response maturity, staffing model, resilience, and control effectiveness rather than marketing breadth.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam