CISM · Question #110
An enterprise has decided to procure security services from a third-party vendor to support its information security program. Which of the following is MOST important to include in the vendor…
The correct answer is C. Alignment of the vendor's business objectives with enterprise security goals. When selecting a third-party vendor for security services, the most important criterion is the alignment of the vendor's business objectives with the enterprise's security goals.
Question
An enterprise has decided to procure security services from a third-party vendor to support its information security program. Which of the following is MOST important to include in the vendor selection criteria?
Options
- AThe maturity of the vendor's internal control environment
- BFeedback from the vendor's previous clients
- CAlignment of the vendor's business objectives with enterprise security goals
- DPenetration testing against the vendor's network
How the community answered
(19 responses)- B11% (2)
- C84% (16)
- D5% (1)
Why each option
When selecting a third-party vendor for security services, the most important criterion is the alignment of the vendor's business objectives with the enterprise's security goals.
The maturity of the vendor's internal control environment is important for their own security, but alignment of objectives is more critical for the strategic success of the partnership.
Feedback from previous clients is useful for due diligence but does not guarantee alignment with the specific enterprise's security goals.
Alignment of the vendor's business objectives with the enterprise's security goals ensures that the third-party's priorities and operational strategies support, rather than conflict with, the organization's security posture and risk appetite. This synergy is crucial for a successful long-term partnership that effectively enhances the enterprise's information security program and addresses its specific needs.
Penetration testing against the vendor's network is a technical security assessment, not a primary criterion for overall strategic vendor selection and partnership alignment.
Concept tested: Vendor selection criteria alignment
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161.pdf
Topics
Community Discussion
No community discussion yet for this question.