nerdexam
CompTIA

CAS-003 · Question #779

The Chief information Officer (CIO) of a large bank, which uses multiple third-party organizations to deliver a service, is concerned about the handling and security of customer data by the parties…

The correct answer is A. Establish a review committee that assesses the importance of suppliers and ranks them. Establishing a review committee that assesses the importance of suppliers and ranks them implements a risk-tiered vendor management approach - high-risk suppliers (those with access to the most sensitive customer data) receive greater scrutiny and more frequent review. This is…

Risk Management

Question

The Chief information Officer (CIO) of a large bank, which uses multiple third-party organizations to deliver a service, is concerned about the handling and security of customer data by the parties. Which of the following should be implemented to BEST manage the risk?

Options

  • AEstablish a review committee that assesses the importance of suppliers and ranks them
  • BEstablish a team using members from first line risk, the business unit, and vendor
  • CEstablish an audit program that regularly reviews all suppliers regardless of the data they
  • DEstablish a governance program that rates suppliers based on their access to data, the type of

How the community answered

(28 responses)
  • A
    79% (22)
  • B
    4% (1)
  • C
    4% (1)
  • D
    14% (4)

Explanation

Establishing a review committee that assesses the importance of suppliers and ranks them implements a risk-tiered vendor management approach - high-risk suppliers (those with access to the most sensitive customer data) receive greater scrutiny and more frequent review. This is a recognized best practice in third-party risk management (TPRM) because it allocates limited resources proportionally to risk. Option B forms a team but lacks a formal governance structure and ranking mechanism. Option C audits all suppliers regardless of data access, which is inefficient and does not prioritize appropriately. Option D describes a governance program that rates suppliers by data access (also strong), but it appears to be cut off in the question text. Option A represents the most complete, actionable governance structure as presented.

Topics

#vendor risk management#third-party risk#data governance#supplier assessment

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice