Certified Information Security Manager CISM · Free Practice Question Medium

Question 47

What is the purpose of classifying third parties according to risk level?
  • A To determine which third parties require site visits
  • B To determine which third parties do not require assessments
  • C To apply the most rigorous assessment methods to the highest risk third parties
  • D To apply the least rigorous assessment methods to the highest risk third parties
Reveal correct answer

Correct answer: C

Explanation

Correct Answer:

To apply the most rigorous assessment methods to the highest risk third parties is correct. Classifying third parties according to risk level helps an organization determine which third parties warrant more rigorous risk assessments.

Incorrect Answers:

To determine which third parties require site visits is incorrect because it does not represent all assessment techniques.

To determine which third parties do not require assessments is incorrect because it is not the best answer.

To apply the least rigorous assessment methods to the highest risk third parties is incorrect because more rigorous assessments would be applied to the highest risk third parties.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need