ExamGecko
Question list
Search
Search

Question 549 - CISM discussion

Report
Export

Which of the following is the MOST effective way to ensure the security of services and solutions delivered by third-party vendors?

A.
Integrate risk management into the vendor management process.
Answers
A.
Integrate risk management into the vendor management process.
B.
Conduct security reviews on the services and solutions delivered.
Answers
B.
Conduct security reviews on the services and solutions delivered.
C.
Review third-party contracts as part of the vendor management process.
Answers
C.
Review third-party contracts as part of the vendor management process.
D.
Perform an audit on vendors' security controls and practices.
Answers
D.
Perform an audit on vendors' security controls and practices.
Suggested answer: A

Explanation:

Integrating risk management into the vendor management process is the most effective way to ensure the security of services and solutions delivered by third-party vendors, as it enables the organization to identify, assess, treat, and monitor the risks associated with outsourcing. Risk management should be applied throughout the vendor life cycle, from selection, contracting, onboarding, monitoring, to termination. Risk management also helps the organization to define the security requirements, expectations, and responsibilities for the vendors, and to evaluate their performance and compliance. (From CISM Review Manual 15th Edition)

asked 01/10/2024
ftere yagoglu
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first