nerdexam
Isaca

CISM · Question #230

Which of the following BEST defines security requirements for an organization that shares information with a business partner?

The correct answer is B. Contractual agreements between the organization and the business partner. When two organizations share information, security requirements must be mutually agreed upon and legally enforceable - a contract (such as a data sharing agreement, NDA, or SLA) achieves both. It binds both parties to specific obligations around confidentiality, access controls,

Submitted by akirajp· Apr 18, 2026Information Security Governance

Question

Which of the following BEST defines security requirements for an organization that shares information with a business partner?

Options

  • ARegulatory directives that define privacy protection requirements for the business partner
  • BContractual agreements between the organization and the business partner
  • CIT governance guidelines agreed to by the organization and the business partner
  • DEstablished information security policies of the business partner

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    88% (38)
  • C
    7% (3)
  • D
    2% (1)

Explanation

When two organizations share information, security requirements must be mutually agreed upon and legally enforceable - a contract (such as a data sharing agreement, NDA, or SLA) achieves both. It binds both parties to specific obligations around confidentiality, access controls, breach notification, and acceptable use. Regulatory directives apply to specific regulated entities and may not cover all aspects of the partnership. IT governance guidelines are typically internal documents with no legal force over a third party. The business partner's own internal policies are not binding on your organization and may not align with your requirements. Only a contractual agreement creates mutual, enforceable obligations.

Topics

#Third-party security#Contractual agreements#Information sharing

Community Discussion

No community discussion yet for this question.

Full CISM Practice