ExamRange

CCISO (712-50) Executive Decision Simulation

This simulation trains you to think like an executive decision maker. Evaluate the business impact, understand governance constraints, and select the optimal strategic path.

Executive Briefing

You are the Chief Information Security Officer (CISO) of FinTrust Global, a multinational financial services firm. Your organization relies heavily on third-party SaaS and cloud infrastructure providers for core banking operations, customer data management, and payment processing. Following a recent high-profile supply chain breach at a major competitor, the Board's Audit Committee has directed you to formalize and tighten the Vendor Risk Management (VRM) program.

Business Context

FinTrust operates under strict regulatory scrutiny. The corporate strategy aggressively leverages outsourcing to reduce operational capital expenditures and accelerate time-to-market for new financial products. However, the firm's risk tolerance for vendor-induced data exposure is extremely low. The VRM program must balance rigorous third-party oversight with the operational reality of managing hundreds of vendors without paralyzing the procurement process or draining internal compliance budgets.

Decision Scenario

Your compliance team is drafting the updated Third-Party Oversight Policy. A critical debate has emerged regarding the review cadence for primary assurance documents—specifically, SSAE16 (now SOC 1/SOC 2) attestation reports provided by critical service providers.

Reviewing these reports too frequently drains your team's resources and creates friction with vendors who do not produce off-cycle reports. Reviewing them too infrequently leaves the firm blind to degrading vendor controls and violates regulatory due diligence expectations. You must establish a definitive, pragmatic policy standard that aligns with standard industry audit cycles.

Question

How often should the SSAE16 report of your vendors be reviewed?

A. Quarterly
B. Semi-annually
C. Bi-annually
D. Annually