712-50 Question 455
Single answerA global company is outsourcing customer support operations to a third-party provider that will handle call recordings, support tickets, and identity verification data for customers in multiple jurisdictions. The procurement team has drafted a Master Service Agreement (MSA) focused on pricing, term, and service levels, and a Statement of Work (SOW) describing staffing and operational processes. As the CISO, you are asked to identify the MOST important contractual addition before signing to reduce security, privacy, and compliance risk.
Which of the following should be added or strengthened FIRST in the procurement documents?
- A
A detailed security and privacy schedule requiring minimum control standards, breach notification timelines, audit/assessment rights, data handling restrictions, subcontractor requirements, and applicable regulatory obligations
- B
A clause requiring the vendor to adopt the company's exact internal security policies and organizational chart without modification
- C
A provision stating that the vendor is solely responsible for all regulatory compliance, eliminating the company's need for oversight once the contract is signed
- D
A commitment from the vendor to obtain cyber insurance at a level determined later, without specifying security obligations in the MSA or SOW
Show answer and explanation
Correct answer: A
Explanation
The best answer is Option 1 because procurement documents such as the MSA, SOW, data processing addenda, and security schedules are where organizations formally define third-party expectations and allocate responsibilities. For vendors handling personal data and sensitive operational information, these documents should include measurable and enforceable requirements covering information security controls, privacy obligations, legal and regulatory compliance, incident management, audit rights, subcontractor oversight, data retention/deletion, and cross-border data handling where relevant.
From a CCISO perspective, this is a governance and risk management issue, not just a legal drafting exercise. A strong contract should distinguish between commercial terms in the MSA, service-specific obligations in the SOW, and specialized requirements in security/privacy addenda. Best practices are consistent with third-party and supply chain guidance such as ISO/IEC 27036 (supplier relationships), NIST SP 800-161 (cyber supply chain risk management), and control expectations commonly mapped from ISO/IEC 27001 Annex A and NIST SP 800-53. Privacy requirements should also align with applicable data protection laws and the organization's data classification, retention, and incident response requirements. The key principle is that security, privacy, and compliance obligations must be explicit, enforceable, and risk-based before services begin.
- A. Correct.
Correct. In a real procurement context, the highest-priority improvement is to explicitly incorporate security, privacy, and compliance requirements into the contractual framework. For a vendor processing personal data and sensitive customer information across jurisdictions, the MSA/SOW should define control expectations such as access control, encryption where appropriate, logging, retention and disposal, data location/transfer constraints, incident and breach notification requirements, right to audit or assess, regulatory cooperation, subcontractor flow-down obligations, and clearly assigned responsibilities. This approach aligns with common third-party risk management and supplier security practices reflected in frameworks such as ISO/IEC 27036, NIST SP 800-161, and privacy contracting expectations under laws like GDPR and similar data protection regimes.
- B. Incorrect.
Incorrect. Requiring a vendor to mirror the company's internal policies exactly is usually impractical and unnecessary. Organizations should define outcome-based and risk-based contractual requirements rather than insist that the supplier replicate internal governance structures or policy documents word-for-word. The objective is to ensure the vendor meets required control and compliance obligations, not to force identical internal operations.
- C. Incorrect.
Incorrect. Regulatory accountability cannot be fully outsourced by contract. Even if a vendor has direct obligations as a processor or service provider, the hiring company typically retains legal, fiduciary, and oversight responsibilities depending on the applicable law and business context. This option reflects a common misconception that contractual transfer of responsibility eliminates the need for governance, monitoring, and due diligence.
- D. Incorrect.
Incorrect. Cyber insurance can be useful as a financial risk transfer mechanism, but it is not a substitute for clearly documented security, privacy, and compliance requirements. Deferring insurance details and omitting operational obligations leaves major gaps in preventive and detective controls, incident handling, and compliance accountability. Insurance complements contractual security requirements; it does not replace them.