Certified Information Security Manager CISM · Free Practice Question Medium
Question 50
When choosing a third-party vendor for security services, what is the most critical risk management consideration?
- A Evaluating the vendor's reputation and history of service delivery
- B Ensuring the vendor's data protection measures meet organizational standards
- C Reviewing the vendor's incident management and response procedures
- D Conducting a detailed financial stability assessment of the vendor
Reveal correct answer
Correct answer: B
Explanation
The Correct Answer: Ensuring the vendor's data protection measures meet organizational standards: Vendor controls must match organizational security standards to prevent potential data breaches and inconsistencies. The Incorrect Answers: Evaluating the vendor's reputation and history of service delivery: Reputation is important, but security controls must directly meet organizational criteria to manage risk effectively. Conducting a detailed financial stability assessment of the vendor: Financial stability is a consideration, but security assurance takes precedence over financial aspects at the risk management stage. Reviewing the vendor's incident management and response procedures: While crucial, ensuring data protection aligns with internal policies and standards is a priority to prevent material risks.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
