712-50 exam dumps

712-50 practice question 445 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 445

Single answerDesign third party selection process

A global manufacturing company plans to outsource its customer support platform to a third-party SaaS provider. The platform will process customer PII, support users in multiple jurisdictions, and integrate with the company's ERP and identity systems. The procurement team wants to accelerate vendor selection by choosing the lowest-cost provider that has a current SOC 2 report. As the CISO, you are asked to design the third-party selection process so it aligns with business goals and reduces security and compliance risk. Which action should you require FIRST to make the selection process effective and defensible?

  1. A

    Establish a risk-based vendor evaluation framework that classifies the service by data sensitivity, criticality, connectivity, and regulatory exposure, then use that classification to define due diligence and selection criteria

  2. B

    Require all candidate providers to sign the company's standard security addendum before any evaluation, since contractual protections are the most important control in third-party risk management

  3. C

    Select the provider with the strongest independent attestation report, because certifications and audit reports provide sufficient assurance for SaaS security

  4. D

    Defer security review until after the business selects its preferred vendor, so the security team can focus only on the final candidate and avoid delaying procurement

Show answer and explanation

Correct answer: A

Explanation

In CCISO practice, designing a third-party selection process is a governance and risk management activity, not merely a procurement task. The most effective first step is to define a risk-based evaluation framework so the organization can apply proportional due diligence based on the service's inherent risk. In this scenario, the vendor will process PII, operate across multiple jurisdictions, and integrate with core systems, all of which increase risk and require structured evaluation criteria before comparing vendors. Best practice is to classify the vendor engagement using factors such as data sensitivity, business criticality, access to systems, concentration risk, operational dependency, and regulatory obligations. That classification should then determine the depth of assessment, required documentation, legal review, security testing evidence, privacy review, and executive approval path. This approach aligns with NIST guidance on supply chain and third-party risk management, including NIST SP 800-161 and NIST SP 800-53 supplier-related controls, as well as ISO/IEC 27036 guidance for supplier relationships. Certifications, reports, and contract terms are important components, but they should be applied after the organization has established what risks matter and how vendors will be evaluated against those risks.

  • A. Correct.

    Correct. A defensible third-party selection process starts with risk-based scoping and classification of the service. For a SaaS platform handling PII, operating across jurisdictions, and integrating with enterprise systems, the organization should first determine inherent risk based on data type, business criticality, access model, integration depth, and legal or regulatory obligations. That classification then drives tailored due diligence requirements, evaluation criteria, stakeholder involvement, and approval thresholds. This is consistent with established third-party risk management practices in frameworks such as NIST SP 800-161, NIST SP 800-53 SR controls, ISO/IEC 27036, and common enterprise procurement governance models.

  • B. Incorrect.

    Incorrect. Contractual controls are important, but they are not the first step in designing the selection process. Requiring a standard addendum before understanding the vendor's risk profile can create a checkbox exercise and may not address the actual risks of the service. Contracts should be informed by the organization's risk assessment and due diligence findings, including data handling, breach notification, right-to-audit, subcontractor oversight, and compliance obligations.

  • C. Incorrect.

    Incorrect. Independent attestations such as SOC 2 reports are useful inputs, but they are not sufficient on their own to select a provider. They may not cover the exact scope of services, integration model, jurisdictional requirements, resilience expectations, or specific customer controls needed. A common misconception is to treat certifications or audit reports as substitutes for a risk-based evaluation. They should support, not replace, the broader selection process.

  • D. Incorrect.

    Incorrect. Security review should not be postponed until after a preferred vendor has been chosen. Doing so weakens governance, increases the likelihood of business lock-in, and makes it harder to compare vendors against consistent security and compliance criteria. Embedding security requirements early in the selection process allows the organization to eliminate unsuitable vendors before procurement momentum and stakeholder bias make risk-based decisions more difficult.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam