ExamGecko
Question list
Search
Search

Question 541 - CISM discussion

Report
Export

Which of the following is the BEST indicator of the maturity level of a vendor risk management process?

A.
Average time required to complete the vendor risk management process
Answers
A.
Average time required to complete the vendor risk management process
B.
Percentage of vendors that have gone through the vendor onboarding process
Answers
B.
Percentage of vendors that have gone through the vendor onboarding process
C.
Percentage of vendors that are regularly reviewed against defined criteria
Answers
C.
Percentage of vendors that are regularly reviewed against defined criteria
D.
Number of vendors rejected because of security review results
Answers
D.
Number of vendors rejected because of security review results
Suggested answer: C

Explanation:

The percentage of vendors that are regularly reviewed against defined criteria is the best indicator of the maturity level of a vendor risk management process, as it reflects the extent to which the organization has established and implemented a consistent, repeatable, and effective process to monitor and evaluate the security performance and compliance of its vendors. A high percentage indicates a mature process that covers all vendors and applies clear and relevant criteria based on the organization's risk appetite and objectives. A low percentage indicates a less mature process that may be ad hoc, incomplete, or outdated. (From CISM Review Manual 15th Edition)

asked 01/10/2024
Ryan Edwards
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first