712-50 Question 450
Single answerA newly appointed CISO is asked to improve executive oversight of third-party technology procurements after an internal audit found inconsistent security requirements in vendor contracts and limited visibility into whether purchased solutions meet corporate security policy. The procurement office wants a quarterly report that is concise, comparable across suppliers, and useful for deciding whether to approve, delay, or remediate purchases. Which reporting approach would BEST measure procurement performance against IT security policies and procedures?
- A
Report the percentage of procurement requests completed within budget and target delivery dates, because operational efficiency is the primary indicator of procurement success
- B
Report a standardized set of security procurement KPIs, such as percentage of vendors that completed security due diligence before contract signature, percentage of contracts containing approved security clauses, number of policy exceptions granted, and remediation status of identified supplier control gaps
- C
Report only the number of critical vulnerabilities identified in procured products after deployment, because technical weaknesses provide the most objective measure of procurement security effectiveness
- D
Report the total annual spend on security-related products and services by business unit, because higher security investment generally indicates better policy alignment
Show answer and explanation
Correct answer: B
Explanation
The best answer is the standardized KPI-based reporting model in Option 2 because the scenario specifically asks for measures and reporting standards aligned with IT security policies and procedures. In executive procurement oversight, the CISO should define metrics that are consistent, auditable, and linked to control objectives across the procurement process. Useful examples include completion of security due diligence before award, inclusion of mandatory security and privacy clauses in contracts, count and trend of approved policy exceptions, supplier risk ratings, and closure status of remediation actions.
This reflects established practices in governance, risk, and third-party security management. NIST SP 800-161 emphasizes managing supply chain risk through defined controls and monitoring. NIST SP 800-53 and common third-party risk programs support documenting security requirements, assessing suppliers, and tracking remediation. ISO/IEC 27001 and ISO/IEC 27036 also support supplier relationship controls, including defining security requirements for supplier agreements and monitoring compliance. From a CCISO perspective, leadership reporting should help executives answer: Are procurement activities complying with policy? Where are exceptions occurring? What residual risks remain? Which vendors or purchases require remediation before approval? Metrics centered only on speed, spend, or post-implementation technical findings do not provide sufficient governance visibility.
- A. Incorrect.
This is incorrect because it focuses on cost and schedule efficiency rather than alignment with IT security policies and procedures. While budget and delivery metrics matter to procurement operations, they do not indicate whether required security reviews, contractual safeguards, or exception handling were completed. A candidate might choose this option because procurement teams often emphasize operational KPIs, but for CCISO governance purposes, security-aligned measures must demonstrate policy compliance and risk treatment, not just process speed.
- B. Correct.
This is correct because it establishes measurable, repeatable, and decision-oriented reporting tied directly to security policy requirements across the procurement lifecycle. These KPIs cover preventive controls before purchase approval, contractual enforcement during vendor onboarding, formal exception management where policy cannot be fully met, and remediation tracking for identified weaknesses. This approach gives executives comparable data across procurements and supports risk-based decisions on approval, delay, or remediation. It also aligns with common third-party risk management and governance practices that emphasize due diligence, contract controls, exception documentation, and ongoing remediation monitoring.
- C. Incorrect.
This is incorrect because it is too narrow and too late in the lifecycle. Post-deployment vulnerabilities are important, but they measure only one outcome after the procurement decision has already been made. They do not indicate whether procurement followed required security procedures such as due diligence, contractual security terms, or exception approval. Someone might choose this option because vulnerability counts appear objective, but by themselves they are not a sufficient reporting standard for procurement governance.
- D. Incorrect.
This is incorrect because spending levels are not a reliable measure of compliance or effectiveness. Higher spend may reflect greater complexity, inefficiency, or poor planning rather than stronger alignment to security policy. This metric also fails to show whether vendors underwent assessment, whether contracts included required clauses, or whether identified risks were accepted or remediated. Candidates may be tempted by this option because budget figures are easy to obtain and report, but they are weak indicators of policy adherence.