nerdexam
Isaca

CISM · Question #110

An enterprise has decided to procure security services from a third-party vendor to support its information security program. Which of the following is MOST important to include in the vendor…

The correct answer is C. Alignment of the vendor's business objectives with enterprise security goals. When selecting a third-party vendor for security services, the most important criterion is the alignment of the vendor's business objectives with the enterprise's security goals.

Submitted by packet_pusher· Apr 18, 2026Information Security Governance

Question

An enterprise has decided to procure security services from a third-party vendor to support its information security program. Which of the following is MOST important to include in the vendor selection criteria?

Options

  • AThe maturity of the vendor's internal control environment
  • BFeedback from the vendor's previous clients
  • CAlignment of the vendor's business objectives with enterprise security goals
  • DPenetration testing against the vendor's network

How the community answered

(19 responses)
  • B
    11% (2)
  • C
    84% (16)
  • D
    5% (1)

Why each option

When selecting a third-party vendor for security services, the most important criterion is the alignment of the vendor's business objectives with the enterprise's security goals.

AThe maturity of the vendor's internal control environment

The maturity of the vendor's internal control environment is important for their own security, but alignment of objectives is more critical for the strategic success of the partnership.

BFeedback from the vendor's previous clients

Feedback from previous clients is useful for due diligence but does not guarantee alignment with the specific enterprise's security goals.

CAlignment of the vendor's business objectives with enterprise security goalsCorrect

Alignment of the vendor's business objectives with the enterprise's security goals ensures that the third-party's priorities and operational strategies support, rather than conflict with, the organization's security posture and risk appetite. This synergy is crucial for a successful long-term partnership that effectively enhances the enterprise's information security program and addresses its specific needs.

DPenetration testing against the vendor's network

Penetration testing against the vendor's network is a technical security assessment, not a primary criterion for overall strategic vendor selection and partnership alignment.

Concept tested: Vendor selection criteria alignment

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161.pdf

Topics

#Vendor management#Third-party risk#Strategic alignment#Service procurement

Community Discussion

No community discussion yet for this question.

Full CISM Practice