The first step is to include information security criteria as part of vendor selection (D). CISM third-party risk management guidance stresses that security requirements must be defined before contracting or performance measurement. Contracts (A), reports (B), and metrics (C) are ineffective if the vendor was not selected based on the organization's security needs. Embedding security criteria early ensures only vendors capable of meeting required controls, compliance, and risk thresholds are considered. References: ISACA CISM Review Manual (Governance-third-party risk management); CISM Exam Content Outline (Domain 2).