Certified Information Security Manager CISM · Free Practice Question Medium
Question 47
- A To determine which third parties require site visits
- B To determine which third parties do not require assessments
- C To apply the most rigorous assessment methods to the highest risk third parties
- D To apply the least rigorous assessment methods to the highest risk third parties
Reveal correct answer
Correct answer: C
Explanation
Correct Answer:
To apply the most rigorous assessment methods to the highest risk third parties is correct. Classifying third parties according to risk level helps an organization determine which third parties warrant more rigorous risk assessments.
Incorrect Answers:
To determine which third parties require site visits is incorrect because it does not represent all assessment techniques.
To determine which third parties do not require assessments is incorrect because it is not the best answer.
To apply the least rigorous assessment methods to the highest risk third parties is incorrect because more rigorous assessments would be applied to the highest risk third parties.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
