nerdexam
Isaca

CISM · Question #268

Which of the following is the BEST approach for an information security manager to effectively manage third-party risk?

The correct answer is A. Ensure vendor contracts are reviewed on an annual basis.. Annual contract review is the best formal mechanism for managing third-party risk because contracts are the primary control instrument governing vendor relationships. Regular review ensures security requirements remain current, SLAs are enforced, compliance obligations are update

Submitted by deeparc· Apr 18, 2026Information Security Risk Management

Question

Which of the following is the BEST approach for an information security manager to effectively manage third-party risk?

Options

  • AEnsure vendor contracts are reviewed on an annual basis.
  • BEnsure risk management efforts are commensurate with risk exposure.
  • CEnsure senior management has approved the vendor relationship.
  • DEnsure controls are implemented to address changes in risk.

How the community answered

(52 responses)
  • A
    62% (32)
  • B
    21% (11)
  • C
    8% (4)
  • D
    10% (5)

Explanation

Annual contract review is the best formal mechanism for managing third-party risk because contracts are the primary control instrument governing vendor relationships. Regular review ensures security requirements remain current, SLAs are enforced, compliance obligations are updated, and the vendor's continued eligibility is confirmed. Option B (commensurate risk management) is a sound principle but describes a general framework, not a specific management action. Option C (senior management approval) is a one-time governance step during onboarding, not ongoing management. Option D (implementing controls for risk changes) is reactive rather than structured. Systematic contract reviews provide the audit trail and accountability structure that third-party risk management requires.

Topics

#Third-party risk management#Vendor management#Contract review#Ongoing risk monitoring

Community Discussion

No community discussion yet for this question.

Full CISM Practice