CISM · Question #268
Which of the following is the BEST approach for an information security manager to effectively manage third-party risk?
The correct answer is A. Ensure vendor contracts are reviewed on an annual basis.. Annual contract review is the best formal mechanism for managing third-party risk because contracts are the primary control instrument governing vendor relationships. Regular review ensures security requirements remain current, SLAs are enforced, compliance obligations are update
Question
Which of the following is the BEST approach for an information security manager to effectively manage third-party risk?
Options
- AEnsure vendor contracts are reviewed on an annual basis.
- BEnsure risk management efforts are commensurate with risk exposure.
- CEnsure senior management has approved the vendor relationship.
- DEnsure controls are implemented to address changes in risk.
How the community answered
(52 responses)- A62% (32)
- B21% (11)
- C8% (4)
- D10% (5)
Explanation
Annual contract review is the best formal mechanism for managing third-party risk because contracts are the primary control instrument governing vendor relationships. Regular review ensures security requirements remain current, SLAs are enforced, compliance obligations are updated, and the vendor's continued eligibility is confirmed. Option B (commensurate risk management) is a sound principle but describes a general framework, not a specific management action. Option C (senior management approval) is a one-time governance step during onboarding, not ongoing management. Option D (implementing controls for risk changes) is reactive rather than structured. Systematic contract reviews provide the audit trail and accountability structure that third-party risk management requires.
Topics
Community Discussion
No community discussion yet for this question.