nerdexam
Isaca

CGEIT · Question #587

Which of the following is the MOST important course of action when initiating a procurement process for a Zero Trust solution?

The correct answer is B. Conduct a thorough assessment of the vendor's security practices.. When procuring a Zero Trust solution, the most critical initial step is to thoroughly assess the vendor's security practices to ensure the solution itself aligns with Zero Trust principles and does not introduce new risks.

Submitted by yasin.bd· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following is the MOST important course of action when initiating a procurement process for a Zero Trust solution?

Options

  • ADevelop a contracting template for solution procurement.
  • BConduct a thorough assessment of the vendor's security practices.
  • CSelect an industry-recognized solution used by a benchmarked enterprise.
  • DDevelop a comprehensive list of required features.

How the community answered

(50 responses)
  • A
    8% (4)
  • B
    72% (36)
  • C
    4% (2)
  • D
    16% (8)

Why each option

When procuring a Zero Trust solution, the most critical initial step is to thoroughly assess the vendor's security practices to ensure the solution itself aligns with Zero Trust principles and does not introduce new risks.

ADevelop a contracting template for solution procurement.

Developing a contracting template is a procedural step in procurement, but it doesn't address the fundamental security implications of the solution itself.

BConduct a thorough assessment of the vendor's security practices.Correct

A Zero Trust solution aims to enhance security by never trusting, always verifying. Therefore, it is paramount that the vendor providing such a solution adheres to robust security practices themselves to prevent supply chain attacks or vulnerabilities in the solution, making their security posture a foundational consideration for a security-critical procurement.

CSelect an industry-recognized solution used by a benchmarked enterprise.

Selecting an industry-recognized solution based on benchmarking might be a factor, but it doesn't guarantee the vendor's specific security practices or suitability for the enterprise's unique Zero Trust needs.

DDevelop a comprehensive list of required features.

While a comprehensive list of features is important, it comes after ensuring the vendor's foundational security integrity, as even a feature-rich solution from an insecure vendor is problematic.

Concept tested: Zero Trust solution procurement security

Source: https://learn.microsoft.com/en-us/security/zero-trust/zero-trust-overview

Topics

#Procurement#Zero Trust#Vendor Management#Security Governance

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice