Certified Information Security Manager CISM · Free Practice Question Medium

Question 50

When choosing a third-party vendor for security services, what is the most critical risk management consideration?
  • A Evaluating the vendor's reputation and history of service delivery
  • B Ensuring the vendor's data protection measures meet organizational standards
  • C Reviewing the vendor's incident management and response procedures
  • D Conducting a detailed financial stability assessment of the vendor
Reveal correct answer

Correct answer: B

Explanation

The Correct Answer: Ensuring the vendor's data protection measures meet organizational standards: Vendor controls must match organizational security standards to prevent potential data breaches and inconsistencies. The Incorrect Answers: Evaluating the vendor's reputation and history of service delivery: Reputation is important, but security controls must directly meet organizational criteria to manage risk effectively. Conducting a detailed financial stability assessment of the vendor: Financial stability is a consideration, but security assurance takes precedence over financial aspects at the risk management stage. Reviewing the vendor's incident management and response procedures: While crucial, ensuring data protection aligns with internal policies and standards is a priority to prevent material risks.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need