712-50 Question 451
Single answerA global enterprise is centralizing third-party technology procurement after several business units purchased SaaS solutions without sufficient security review. The CISO has been asked to establish measures and reporting standards that allow executive leadership to see whether procurement activities are aligned with the organization's IT security policies and procedures. Which metric and reporting approach would BEST demonstrate both policy compliance and risk visibility across the procurement lifecycle?
- A
Report the total number of vendors onboarded each quarter and the percentage that offered the lowest purchase price, since cost efficiency is the primary procurement objective.
- B
Report the percentage of procurements that completed required security due diligence before contract execution, the number of policy exceptions approved, the aging of unresolved supplier security findings by risk level, and trend these measures against defined thresholds in a standardized dashboard.
- C
Report the number of security questionnaires sent to prospective suppliers and the average time the security team took to respond to procurement requests, because activity volume demonstrates control effectiveness.
- D
Report only critical findings identified during vendor assessments to avoid overwhelming executives with operational details and to keep reporting focused on the highest risks.
Show answer and explanation
Correct answer: B
Explanation
The best answer is the option that establishes measurable, policy-linked, and risk-based procurement reporting. In a CCISO context, leadership needs reporting that answers key governance questions: Are required security reviews occurring before commitments are made? Where are exceptions being granted, and are they formally approved? What supplier risks remain unresolved, and how long have they been open? Effective measures should be standardized, consistently defined, and tied to thresholds or risk appetite so that trends and deviations can be escalated. This is consistent with recognized practices in third-party risk management, security governance, and procurement oversight found in frameworks and guidance such as NIST SP 800-161 for cyber supply chain risk management, NIST SP 800-53 controls related to external service providers and supply chain protection, ISO/IEC 27001 and 27002 guidance on supplier relationships and information security controls, and common governance principles emphasizing metrics that are relevant, actionable, and aligned to policy objectives. Good reporting distinguishes between activity metrics, compliance metrics, and risk metrics, with the strongest executive dashboards combining all three but prioritizing compliance and residual risk over simple operational volume.
- A. Incorrect.
This is incorrect because it focuses on commercial efficiency rather than alignment with IT security policies and procedures. While procurement leaders may track savings and vendor volume, these measures do not show whether mandatory security reviews occurred, whether exceptions were properly governed, or whether identified risks were remediated before or after onboarding. A candidate might choose this option if they confuse procurement performance metrics with security governance metrics.
- B. Correct.
This is correct because it combines leading and lagging indicators tied directly to policy compliance and residual risk. Measuring completion of required security due diligence before contract execution shows whether procurement is following mandated controls. Tracking approved policy exceptions provides governance visibility into deviations from standard requirements. Monitoring aging of unresolved supplier security findings by risk level shows whether identified issues are being addressed in line with risk tolerance. Trending against thresholds in a standardized dashboard supports consistent executive reporting, accountability, and escalation. This approach aligns with common third-party risk management and governance practices, where metrics should be measurable, repeatable, risk-based, and mapped to policy requirements.
- C. Incorrect.
This is incorrect because it measures process activity, not control effectiveness or alignment with policy. Sending questionnaires does not mean the supplier was properly assessed, approved, or contractually bound to security requirements. Average response time may be useful as an operational efficiency metric, but by itself it does not tell leadership whether procurement decisions complied with security procedures or whether supplier risk is being managed appropriately. This reflects a common misconception that high process throughput equals effective governance.
- D. Incorrect.
This is incorrect because reporting only critical findings creates a narrow and potentially misleading view of procurement risk. Executive reporting should support oversight of compliance, exception management, and remediation trends across risk levels, especially where moderate or high findings remain unresolved for long periods. Omitting broader indicators also makes it harder to identify systemic control failures, such as business units bypassing required due diligence. Someone might choose this option because executive reports should be concise, but concision should not come at the expense of meaningful governance information.