712-50 Question 452
Single answerA global manufacturing company is outsourcing operation of a cloud-based supplier portal that will process proprietary designs and limited personal data from vendors in multiple jurisdictions. The procurement team has drafted the acquisition package with standard uptime targets and a generic confidentiality clause, but no security-specific language. The CIO wants the contract awarded within six weeks. As the CISO, which action is the BEST way to ensure the procurement documents reflect risk-based security requirements without unnecessarily delaying the award?
- A
Require all bidders to sign the company's standard NDA and rely on post-award security policies to define controls during onboarding.
- B
Update the acquisition plan, statement of work, evaluation criteria, cost estimate, and draft SLA to include security requirements derived from a risk assessment, such as data protection obligations, incident notification timeframes, logging, access control, audit rights, and jurisdictional compliance responsibilities.
- C
Add a clause stating that the selected vendor must be compliant with industry best practices and let the legal team negotiate specific security terms after the vendor is chosen.
- D
Delay the procurement until the security team completes a full enterprise-wide control redesign so that one universal set of controls can be applied to all future vendor contracts.
Show answer and explanation
Correct answer: B
Explanation
The best answer is Option 2 because effective third-party risk management requires security requirements to be incorporated into procurement artifacts before award, not handled informally or deferred until after selection. In a CCISO context, this reflects governance, risk management, and strategic alignment: security must influence sourcing decisions, pricing assumptions, contractual accountability, and service expectations. A risk-based approach starts with understanding the data involved, business criticality, threat exposure, regulatory obligations, and dependency on the provider. Those findings should then flow into acquisition plans, statements of work, evaluation criteria, cost estimates, contract clauses, and SLAs.
Relevant best practices are reflected in established guidance such as NIST SP 800-161 on supply chain risk management, NIST SP 800-53 controls related to system and services acquisition and supplier oversight, and ISO/IEC 27036 on supplier relationships. Common themes across these sources include defining security requirements up front, assigning responsibilities clearly, establishing monitoring and audit rights, addressing incident management and notification, and ensuring requirements are proportionate to risk. This approach enables better vendor comparison, stronger enforceability, and reduced residual risk while still supporting business timelines.
- A. Incorrect.
This is incorrect because an NDA and post-award policy discussions do not sufficiently embed enforceable, risk-based security requirements into the procurement lifecycle. Relying on onboarding after contract award weakens the organization's leverage, may create ambiguity over accountability, and often leads to scope disputes or unbudgeted remediation. The misconception is that confidentiality language alone adequately addresses third-party security risk; in practice, confidentiality is only one component and does not cover operational controls, breach response, monitoring, auditability, or regulatory obligations.
- B. Correct.
This is correct because it integrates security requirements where they have the greatest contractual and commercial effect: acquisition planning, the statement of work, evaluation factors, cost estimates, contract terms, and SLAs. A risk-based approach means the required controls are tailored to the portal's data sensitivity, exposure, service criticality, and legal obligations across jurisdictions. Including concrete requirements such as encryption, access management, log retention, breach notification, right to audit, subcontractor oversight, and compliance responsibilities helps ensure vendors price and propose against the same baseline, allowing a fairer comparison and reducing downstream negotiation risk.
- C. Incorrect.
This is incorrect because vague references to 'industry best practices' are typically too ambiguous to be enforceable or measurable. Deferring specifics until after vendor selection undermines meaningful security evaluation during source selection and may result in choosing a lower-cost vendor that did not account for required controls. A common misconception is that legal can refine security later without procurement impact; however, material security obligations affect scope, cost, feasibility, and award decisions and should therefore be included before selection.
- D. Incorrect.
This is incorrect because it overcorrects and introduces unnecessary delay. The scenario asks for the best way to address procurement risk without unnecessarily delaying the award. A full enterprise-wide control redesign is not required to establish risk-based requirements for this specific acquisition. The misconception is that consistency requires a universal, one-time master control set; mature procurement instead uses baseline standards with tailoring based on the service, data, and threat profile.