712-50 Question 446
Single answerDesign third party management policy, metrics, and processesA newly appointed CISO is formalizing a global third-party risk management program after a business unit onboarded a cloud-based customer analytics vendor without security review. The board has asked for a third-party management policy, supporting metrics, and repeatable processes that reduce unmanaged vendor risk without unnecessarily slowing procurement. Which action should the CISO take FIRST to establish an effective foundation for the program?
- A
Create a risk-tiering methodology that classifies third parties by data sensitivity, connectivity, criticality, and regulatory impact, then require due diligence and monitoring processes based on the assigned tier
- B
Mandate that every third party complete the same comprehensive security assessment annually to ensure consistency across the vendor population
- C
Require procurement to sign contracts only with vendors that already hold a recognized security certification, such as ISO/IEC 27001, and waive further review
- D
Track the total number of third parties onboarded each quarter as the primary program metric, since growth in visibility indicates improved third-party governance
Show answer and explanation
Correct answer: A
Explanation
The best first step is to establish a risk-tiering methodology and make it the basis for policy, metrics, and operational processes. In a CCISO context, the CISO must design governance that is defensible, scalable, and aligned to business operations. A sound third-party management policy should define ownership, scope, risk classification criteria, due diligence requirements, approval authorities, contract/security clauses, continuous monitoring, reassessment triggers, issue management, and offboarding requirements. Metrics should then measure both coverage and effectiveness, such as the percentage of third parties inventoried, tiered, assessed pre-contract, monitored on schedule, and remediated within target timelines. This risk-based model is consistent with NIST SP 800-161 on cyber supply chain risk management, ISO/IEC 27036 on supplier relationships, and common regulatory expectations in financial services, privacy, and operational resilience frameworks. The central principle is proportionality: apply deeper scrutiny and stronger controls where the business impact and exposure are greatest.
- A. Correct.
This is correct because a risk-based segmentation model is the foundation of a scalable third-party management program. It allows the organization to tailor due diligence, contractual requirements, approval workflows, continuous monitoring, and reassessment frequency according to the vendor's inherent and residual risk. In practice, factors such as access to sensitive data, integration with internal systems, business criticality, concentration risk, and legal/regulatory exposure are commonly used to define tiers. This approach aligns with widely accepted practices in NIST SP 800-161, NIST Cybersecurity Framework supply chain concepts, ISO/IEC 27036, and regulator expectations that vendor oversight be proportionate to risk.
- B. Incorrect.
This is incorrect because applying the same exhaustive assessment to all third parties is inefficient and not risk-based. It can delay procurement, overwhelm security reviewers, and waste effort on low-risk vendors such as office supply providers that do not process data or connect to systems. A common misconception is that uniformity equals maturity; in reality, mature programs are consistent in governance but differentiated in control depth based on risk tier.
- C. Incorrect.
This is incorrect because certifications can be useful evidence, but they are not a substitute for the organization's own due diligence. A vendor may have a valid certification and still present unacceptable risk due to the specific service scope, data handling model, subcontractor use, geographic considerations, incident history, or contractual gaps. Waiving further review based solely on certification is a common governance error and does not satisfy a tailored risk assessment process.
- D. Incorrect.
This is incorrect because counting onboarded vendors is only a volume metric and does not meaningfully measure risk reduction or process effectiveness. Useful third-party metrics typically include percentage of vendors inventoried and tiered, percentage of high-risk vendors assessed before contract execution, remediation aging for critical findings, exception rates, reassessment timeliness, and incidents attributable to third parties. Focusing primarily on vendor count can create a false sense of control.