ExamGecko
Question list
Search
Search

Question 663 - CISM discussion

Report
Export

An enterprise has decided to procure security services from a third-party vendor to support its information security program. Which of the following is MOST important to include in the vendor selection criteria?

A.
Feedback from the vendor's previous clients
Answers
A.
Feedback from the vendor's previous clients
B.
Alignment of the vendor's business objectives with enterprise security goals
Answers
B.
Alignment of the vendor's business objectives with enterprise security goals
C.
The maturity of the vendor's internal control environment
Answers
C.
The maturity of the vendor's internal control environment
D.
Penetration testing against the vendor's network
Answers
D.
Penetration testing against the vendor's network
Suggested answer: B

Explanation:

The most important thing to include in the vendor selection criteria when procuring security services from a third-party vendor is B. Alignment of the vendor's business objectives with enterprise security goals. This is because the vendor should be able to understand and support the enterprise's security vision, mission, strategy, and policies, and provide services that are consistent and compatible with them. The vendor should also be able to demonstrate how their services add value, reduce risk, and enhance the performance and maturity of the enterprise's information security program. The alignment of the vendor's business objectives with enterprise security goals can help to ensure a successful and long-term partnership, and avoid any conflicts, gaps, or issues that may arise from misalignment or divergence.

The vendor should be able to understand and support the enterprise's security vision, mission, strategy, and policies, and provide services that are consistent and compatible with them. (From CISM Manual or related resources)

Reference = CISM Review Manual 15th Edition, Chapter 3, Section 3.2.1, page 1341; Third-Party Vendor Selection: If Done Right, It's a Win-Win2; Vendor Selection Criteria: Key Factors in Procurement Success3

asked 01/10/2024
tho nguyen
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first