712-50 exam dumps

712-50 practice question 453 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 453

Single answer

A global manufacturing company is procuring a third-party managed detection and response (MDR) service that will ingest logs from plants in multiple countries, connect to cloud workloads, and handle incident escalation for critical production systems. The procurement team wants to accelerate award by using a generic statement of work and adding security terms after vendor selection. As the CISO, you are asked how to ensure the procurement package properly reflects organizational risk before release. Which action is the MOST appropriate?

  1. A

    Require bidders to provide their standard security brochure during due diligence, and negotiate specific logging, incident reporting, and data handling controls after contract award.

  2. B

    Embed risk-based security requirements in the acquisition plan, independent cost estimate, statement of work, contract clauses, service level agreements, and source selection criteria so vendors are evaluated on their ability to meet defined security outcomes.

  3. C

    Rely on the legal team to insert a general compliance clause requiring the selected vendor to follow all applicable laws and industry standards, since detailed security requirements can limit competition.

  4. D

    Select the vendor with the strongest security certifications first, then conduct a post-award gap assessment to determine which technical and operational controls should be added through change orders.

Show answer and explanation

Correct answer: B

Explanation

The best answer is to incorporate risk-based security requirements throughout the procurement lifecycle before solicitation and award. In executive security governance, this means translating business risk, regulatory obligations, data sensitivity, criticality of service, and third-party exposure into acquisition artifacts such as the acquisition plan, statement of work, pricing assumptions, contract terms, service level agreements, and evaluation criteria. This aligns with widely accepted procurement and third-party risk management practices, including NIST SP 800-161 for supply chain risk management, NIST SP 800-53 control families such as SR and SA for supplier and system acquisition considerations, and common vendor risk governance practices that emphasize defining security requirements up front rather than relying on post-award negotiation. For a high-impact outsourced security service, the organization should define measurable requirements such as incident notification timelines, evidence preservation, privileged access management, data location constraints, subcontractor controls, audit rights, business continuity expectations, and reporting obligations. Doing so improves vendor comparability, supports defensible source selection, reduces downstream contract disputes, and ensures the awarded service is aligned to enterprise risk appetite and operational needs.

  • A. Incorrect.

    This is incorrect because security requirements that are deferred until after award reduce the organization's leverage, create scope ambiguity, and increase the likelihood of unbudgeted change requests. A vendor's marketing materials or generic due diligence responses are not a substitute for explicitly defined security, privacy, resilience, and reporting requirements in the procurement documents.

  • B. Correct.

    This is correct because the CISO should ensure security requirements are built into all relevant procurement artifacts from the outset based on business and risk context. For an MDR service supporting critical production operations, that includes requirements for log protection, incident notification timeframes, investigation support, data residency or transfer constraints, privileged access controls, retention, evidence handling, resilience, breach cooperation, audit rights, and measurable service levels. Including these in evaluation factors and cost estimates ensures vendors are compared fairly and that the selected solution is both secure and realistically funded.

  • C. Incorrect.

    This is incorrect because broad legal or compliance language does not translate risk into enforceable operational requirements. General compliance clauses rarely define measurable control expectations such as detection coverage, response time commitments, access restrictions, or reporting obligations. The misconception is that regulatory alignment alone is enough; in practice, security requirements must be tailored to the service and the organization's risk exposure.

  • D. Incorrect.

    This is incorrect because certifications can be useful indicators, but they do not prove the vendor can meet the organization's specific operational, contractual, and risk-based requirements. Waiting until after award to identify gaps often results in rework, delays, increased costs, and disputed accountability. The error is treating certifications as a replacement for detailed acquisition planning and source selection criteria.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam