nerdexam
Isaca

CGEIT · Question #506

Which of the following is the BEST way to manage the risk associated with outsourcing critical IT services?

The correct answer is B. Define controls within service level agreements (SLAs). The most effective way to manage risks from outsourced IT services is by embedding specific controls directly into the Service Level Agreements (SLAs) with the vendor. This contractual approach ensures that security and performance expectations are clearly defined and…

Submitted by krish.m· Apr 18, 2026Risk Optimization

Question

Which of the following is the BEST way to manage the risk associated with outsourcing critical IT services?

Options

  • AEnsure vendors hold information security certifications.
  • BDefine controls within service level agreements (SLAs).
  • CConduct quarterly performance reviews.
  • DEnsure exit clauses are added to the contract.

How the community answered

(62 responses)
  • A
    23% (14)
  • B
    60% (37)
  • C
    6% (4)
  • D
    11% (7)

Why each option

The most effective way to manage risks from outsourced IT services is by embedding specific controls directly into the Service Level Agreements (SLAs) with the vendor. This contractual approach ensures that security and performance expectations are clearly defined and enforceable.

AEnsure vendors hold information security certifications.

Information security certifications demonstrate a vendor's general capability but do not guarantee specific controls or performance for *your* critical services, nor do they provide a direct enforcement mechanism for risk management in an ongoing operational context.

BDefine controls within service level agreements (SLAs).Correct

Defining controls within SLAs provides a legally binding framework for managing risks associated with critical outsourced IT services. SLAs specify the performance, availability, security, and other operational metrics that the vendor must adhere to, making non-compliance actionable and ensuring risk mitigation is contractually enforced.

CConduct quarterly performance reviews.

Quarterly performance reviews are a monitoring activity, important for assessing adherence, but they do not establish or enforce the foundational controls necessary to manage risks in the first place.

DEnsure exit clauses are added to the contract.

Exit clauses are crucial for contingency planning and contract termination, but they do not actively manage or mitigate the operational risks of critical services *during* the contract's active period.

Concept tested: Outsourcing risk management via SLAs

Topics

#Outsourcing Risk Management#Service Level Agreements (SLAs)#Vendor Management#IT Control Definition

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice