nerdexam
Isaca

CISM · Question #210

An organization is in the process of selecting a third party to process customer information. Which of the following provides the BEST evidence that the third party's controls will operate as…

The correct answer is D. An independent assessment. The best evidence that the third party’s controls will operate as required is provided by an independent assessment. Independent assessments, such as third-party audits or certifications (e.g., SOC 2, ISO 27001), offer objective, credible evidence that the third party has…

Submitted by rania.sa· Apr 18, 2026Information Security Risk Management

Question

An organization is in the process of selecting a third party to process customer information. Which of the following provides the BEST evidence that the third party’s controls will operate as required?

Options

  • AAn information security questionnaire
  • BAn external vulnerability assessment
  • CResults of incident response tests
  • DAn independent assessment

How the community answered

(42 responses)
  • A
    12% (5)
  • B
    2% (1)
  • C
    5% (2)
  • D
    81% (34)

Explanation

The best evidence that the third party’s controls will operate as required is provided by an independent assessment. Independent assessments, such as third-party audits or certifications (e.g., SOC 2, ISO 27001), offer objective, credible evidence that the third party has implemented and is maintaining the necessary security controls.

Topics

#Third-party risk management#Vendor due diligence#Control assurance#Independent assessments

Community Discussion

No community discussion yet for this question.

Full CISM Practice