712-50 exam dumps

712-50 practice question 448 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 448

Single answerDesign and manage the third-party assessment process including ongoing compliance management

A newly appointed CISO is redesigning the organization's third-party risk management program after an incident in which a payroll vendor failed to apply a critical security patch for several weeks. The company relies on more than 200 vendors, ranging from cloud-based HR systems to niche data processors. Senior leadership wants a process that is scalable, defensible to auditors, and effective at identifying vendors whose security posture degrades after onboarding. Which approach would BEST meet these objectives?

  1. A

    Require all vendors to complete the same annual security questionnaire and only reassess them during contract renewal to keep the process consistent and efficient.

  2. B

    Implement a risk-tiered assessment process based on data sensitivity, connectivity, and business criticality; require contract clauses for security notifications and audit rights; and perform ongoing monitoring for high-risk vendors using evidence reviews and trigger-based reassessments.

  3. C

    Outsource all third-party assessments to the procurement department and rely on vendor attestations such as marketing security summaries unless a breach becomes public.

  4. D

    Assess vendors only before onboarding, because contractual liability and cyber insurance transfer most of the residual risk after the relationship begins.

Show answer and explanation

Correct answer: B

Explanation

The best answer is the risk-tiered, ongoing monitoring model because CCISO-level leadership is expected to design a program that is both governance-driven and operationally sustainable. Industry best practice from sources such as NIST SP 800-161 on supply chain risk management, NIST SP 800-53 control families related to external systems and continuous monitoring, ISO/IEC 27036 on supplier relationships, and common regulatory expectations all support a lifecycle approach: classify vendors by inherent risk, perform due diligence appropriate to that risk, embed security and compliance obligations in contracts, and continuously monitor for changes in posture. High-risk vendors should not be treated the same as low-risk vendors, and reassessment should occur not only on a calendar basis but also when trigger events occur, such as incidents, material control changes, mergers, or negative audit results. This approach gives leadership better visibility into residual risk and provides stronger assurance that third-party compliance is maintained after onboarding.

  • A. Incorrect.

    This is incorrect because a uniform annual questionnaire ignores inherent risk differences between vendors. Low-risk vendors may be over-assessed, while high-risk vendors may not receive enough scrutiny. It also fails to address ongoing compliance degradation between annual reviews. Mature third-party risk programs use risk-based due diligence and continuous or event-driven monitoring rather than relying solely on periodic questionnaires.

  • B. Correct.

    This is correct because it combines the core elements of an effective third-party assessment process: risk segmentation, contractual enforcement, and ongoing compliance management. Risk-tiering based on factors such as data classification, system access, transaction volume, and criticality aligns resources to the vendors that matter most. Contract provisions for breach notification, right to audit, control requirements, and remediation timelines support governance. Ongoing monitoring through updated SOC reports, control evidence, external intelligence, performance metrics, and trigger events such as major control changes or incidents is the most scalable and defensible approach.

  • C. Incorrect.

    This is incorrect because procurement is an important stakeholder but should not own security risk decisions in isolation. Relying on vendor self-assertions or marketing materials does not provide sufficient assurance and would be difficult to defend to internal audit, regulators, or customers. Effective programs typically involve security, legal, procurement, privacy, and business owners, with security performing or directing the control assessment.

  • D. Incorrect.

    This is incorrect because risk is not transferred simply by signing a contract or purchasing cyber insurance. The organization retains accountability for managing third-party risk, especially where vendors process sensitive data or support critical services. Pre-onboarding assessment is necessary but insufficient; control effectiveness can change over time due to staff turnover, new subcontractors, architecture changes, incidents, or audit findings.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam