Secure Acquisition And Procurement for Security+
Short answer
Procurement has security impact because decisions made before purchase can create or reduce risk for years. A hardware asset that cannot receive firmware updates may become unsafe before its business use ends. A software asset without support, patching, or clear licensing may become a liability even if it solves a short-term need. A data asset acquired from a third party may carry retention, sensitivity, privacy, or usage constraints. Security review during acquisition should ask whether the asset can be supported, tracked, patched, protected, and eventually disposed of correctly.
Why it appears on the exam
SY0-701 4.2: Explain how acquisition and procurement decisions affect hardware, software, and data security.
Key concepts
Concept 1
Required terms
acquisition: obtaining an asset for organizational use, whether by purchase, lease, subscription, transfer, or creation. procurement: the formal process used to request, evaluate, approve, purchase, and receive assets. hardware asset: a physical technology item such as a laptop, server, mobile device, network device, drive, or embedded device. software asset: an application, operating system, service subscription, library, license, or code package used by the organization.
Example
A department wants to buy a low-cost network camera. Procurement security review asks whether default credentials can be changed, firmware updates are available, support lifecycle is clear, and the device can be inventoried.
Concept 2
How Secure Acquisition And Procurement works
Procurement has security impact because decisions made before purchase can create or reduce risk for years. A hardware asset that cannot receive firmware updates may become unsafe before its business use ends. A software asset without support, patching, or clear licensing may become a liability even if it solves a short-term need. A data asset acquired from a third party may carry retention, sensitivity, privacy, or usage constraints. Security review during acquisition should ask whether the asset can be supported, tracked, patched, protected, and eventually disposed of correctly.
Example
A team subscribes to a SaaS tool that stores customer data. The acquisition process should check data handling, authentication support, export and deletion options, retention terms, and ownership of the business data.
Concept 3
Common confusion
Procurement security is not the same as supply chain attack analysis. Supply chain threats can matter, but this micro-objective asks how proper asset management during acquisition and procurement affects security outcomes such as supportability, tracking, ownership, licensing, and data handling.
Example
A legacy application is cheaper than a supported alternative but reaches end of support in six months. Procurement should treat that support lifecycle as a security implication, not only a budget issue.
Concept 4
What to recognize
Identify security questions that should be asked before buying or subscribing to hardware, software, or data; Choose procurement review when a new asset may be unsupported, unlicensed, untracked, or unable to meet security requirements; Explain why support lifecycle, updates, logging, authentication, and retention terms matter before acquisition; Distinguish procurement review from post-deployment hardening or vulnerability scanning.
Example
A data set is purchased for analytics. The organization needs to know its classification, allowed uses, retention period, and disposal requirements before loading it into production systems.
Sample questions
Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.
Q1.A security team sees this situation: A team subscribes to a SaaS tool that stores customer data. The acquisition process should check data handling, authentication support, export and deletion options, retention terms, and ownership of the busines... Which concept applies?
Q2.A Security+ scenario describes this situation: A department wants to buy a low-cost network camera. Procurement security review asks whether default credentials can be changed, firmware updates are available, support lifecycle is clear, and the device can b... Which answer fits best?
Q3.For this Security+ objective, the scenario says: A legacy application is cheaper than a supported alternative but reaches end of support in six months. Procurement should treat that support lifecycle as a security implication, not only a budget issue. Which concept should you choose?
Practice this lesson in Cultiv8
The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.
Continue in Cultiv8