712-50 Question 447
Single answerDesign third party management policy, metrics, and processesA newly appointed CISO is redesigning the organization's third-party risk management program after a regulator found that vendor oversight was inconsistent across business units. Some teams perform detailed due diligence, while others onboard suppliers with only a procurement review. The CISO must propose a policy and operating model that improves risk visibility, supports executive reporting, and can be applied consistently to cloud providers, managed service providers, and data-processing vendors. Which approach is the MOST effective?
- A
Require all third parties to complete the same comprehensive security assessment annually so the process is standardized and easier to audit.
- B
Create a risk-based third-party management policy that classifies vendors by inherent risk and criticality, defines due diligence and reassessment requirements by tier, and tracks metrics such as assessment completion, remediation aging, exception volume, and concentration risk.
- C
Delegate third-party security decisions entirely to procurement because procurement owns the supplier relationship and can enforce contract terms more efficiently than security.
- D
Focus the policy primarily on adding stronger contract clauses, assuming legal protections will sufficiently reduce the organization's exposure from third-party failures.
Show answer and explanation
Correct answer: B
Explanation
The best answer is the risk-based third-party management policy and operating model. In practice, leading frameworks and guidance emphasize proportional oversight rather than one-size-fits-all assessments. NIST SP 800-161 highlights managing supply chain risk through governance, criticality analysis, and ongoing monitoring. NIST SP 800-53 controls such as SR family controls support supplier assessments, contracts, and monitoring, while ISO/IEC 27001 and ISO/IEC 27036 stress supplier relationship controls, security requirements, and lifecycle management. From a CCISO perspective, the key is designing a policy, metrics, and process architecture that is repeatable, risk-aligned, and meaningful to executives. Useful metrics should help answer whether the organization knows which vendors matter most, whether required reviews are happening on time, whether identified issues are being remediated within tolerance, and whether systemic dependencies are creating concentration risk. A mature program also defines governance, ownership, escalation paths, exceptions handling, reassessment triggers, and linkage to procurement and contract management.
- A. Incorrect.
This is not the most effective approach because it emphasizes uniformity over risk-based governance. Applying the same deep assessment to every vendor wastes resources on low-risk suppliers and can delay business operations, while still failing to ensure that the highest-risk vendors receive proportionately greater scrutiny. Mature third-party programs use tiering based on factors such as data sensitivity, service criticality, network connectivity, regulatory impact, and substitutability.
- B. Correct.
This is correct because a risk-based policy is the foundation of an effective third-party management program. Classifying vendors by inherent risk and business criticality allows the organization to define proportionate onboarding reviews, contract requirements, monitoring frequency, and reassessment intervals. The listed metrics are also appropriate for executive and operational oversight: assessment completion shows process coverage, remediation aging highlights unresolved exposure, exception volume reveals policy bypasses or control gaps, and concentration risk identifies overreliance on a small number of key providers. This approach supports consistency, governance, and scalable decision-making.
- C. Incorrect.
This is incorrect because procurement is an important stakeholder, but third-party risk decisions should not be delegated entirely to procurement. Procurement typically manages commercial relationships and sourcing processes, while security, privacy, legal, compliance, and business owners each provide input on risk. Effective governance requires clear roles and responsibilities across these functions rather than transferring sole ownership to one team.
- D. Incorrect.
This is incorrect because contract clauses are necessary but not sufficient. Contracts can establish security obligations, audit rights, incident notification timelines, and liability terms, but they do not replace due diligence, ongoing monitoring, or performance metrics. A vendor can still fail operationally or experience a breach even when the contract language is strong. Relying mainly on legal wording reflects a common misconception that risk can be transferred entirely through contracts.