712-50 exam dumps

712-50 practice question 454 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 454

Single answer

A global healthcare company is outsourcing customer support operations to a third-party provider that will process protected health information (PHI) and personal data for patients in multiple jurisdictions. Procurement has circulated a draft Master Service Agreement (MSA) that contains standard commercial terms, confidentiality language, and pricing, but the attached Statement of Work (SOW) only describes service volumes and staffing levels. As the CISO, you are asked what procurement documentation should be added or strengthened before contract signature to best reduce security, privacy, and compliance risk while preserving enforceability. Which of the following is the BEST recommendation?

  1. A

    Rely on the MSA confidentiality clause and require the provider to submit its internal security policy after signing, since operational controls can be finalized during onboarding

  2. B

    Add enforceable security and privacy requirements to the SOW and related exhibits, including minimum control expectations, breach/incident notification timelines, audit/assessment rights, subcontractor restrictions, data handling and retention requirements, regulatory obligations, and measurable service levels tied to compliance

  3. C

    Move all security and privacy requirements into a nonbinding vendor questionnaire so the company can update expectations without reopening the contract

  4. D

    Accept the provider's SOC 2 report in lieu of contractual security terms, because independent assurance reports are sufficient evidence that the provider will meet healthcare privacy and security obligations

Show answer and explanation

Correct answer: B

Explanation

The best answer is to strengthen the binding procurement documents themselves, especially where a vendor will handle regulated or sensitive data. In practice, security, privacy, and compliance obligations are often allocated across the MSA, SOW, data processing addendum, security exhibit, and sector-specific addenda such as a Business Associate Agreement when PHI is involved. The key principle is that due diligence evidence and internal vendor policies are not enough by themselves; the organization must ensure that material obligations are contractually enforceable.

Best practices from third-party risk management and procurement governance generally call for contracts to address: scope of data processing; information security minimum controls; incident and breach notification timing; audit and evidence rights; regulatory cooperation; data retention, return, and destruction; subcontractor oversight and flow-down clauses; cross-border transfer and residency requirements where applicable; service levels and remedies; and termination rights for material security or compliance failures. These principles are consistent with widely used control frameworks and guidance such as NIST SP 800-161 for supply chain risk management, NIST SP 800-53 control families related to external service providers and incident response, ISO/IEC 27001 and 27036 guidance for supplier relationships, and privacy contracting practices reflected in GDPR processor terms and HIPAA business associate arrangements where applicable. A mature CISO ensures these expectations are embedded in the procurement documents before signature so they are measurable, enforceable, and aligned to the organization's risk appetite.

  • A. Incorrect.

    This is incorrect because a general confidentiality clause does not adequately address the full range of third-party security, privacy, and compliance obligations. For services involving PHI and personal data, the organization should define explicit contractual requirements before execution, not defer them until onboarding. Post-signature policy submissions may help operationally, but they do not provide the same enforceable protections as contract terms.

  • B. Correct.

    This is correct because high-risk outsourcing arrangements should include clear, enforceable requirements in the SOW, MSA, and supporting exhibits or schedules. These typically include security control baselines, privacy and lawful processing obligations, incident and breach notification requirements, audit rights, data location and transfer restrictions where relevant, subcontractor approval/flow-down obligations, retention and secure disposal requirements, right-to-terminate for material compliance failures, and service levels or remedies tied to critical obligations. This approach aligns legal enforceability with operational expectations.

  • C. Incorrect.

    This is incorrect because a nonbinding questionnaire is useful during due diligence but is not a substitute for contract language. Questionnaires can inform vendor selection and risk assessment, but if the requirements are not incorporated into binding procurement documents, the company may have limited recourse if the provider fails to meet them.

  • D. Incorrect.

    This is incorrect because assurance reports such as SOC 2 can support due diligence, but they do not replace customer-specific contractual obligations, especially in regulated environments such as healthcare. A SOC 2 report may not address all applicable privacy, breach reporting, data residency, subcontracting, or sector-specific requirements. Contract terms are still needed to define obligations and remedies.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam