nerdexam
Isaca

CISM · Question #300

Which of the following is the MOST effective method to ensure organizations have adequate security controls over outsourced services?

The correct answer is C. Require regular security compliance audits by an agreed.to independent third party. Contractual requirements and policy mandates (Choices B and D) establish what the provider should do but offer no independent verification that they actually do it. Regular reviews of the provider's own policies (Choice A) are self-assessed and lack objectivity. Independent…

Submitted by jaden.t· Apr 18, 2026Information Security Risk Management

Question

Which of the following is the MOST effective method to ensure organizations have adequate security controls over outsourced services?

Options

  • ARequire regular reviews of the service provider's security policies and processes.
  • BRequire a signed contract obliging the service provider to implement industry best practices.
  • CRequire regular security compliance audits by an agreed.to independent third party.
  • DRequire the service provider to use the organization's security policies and standards.

How the community answered

(48 responses)
  • A
    17% (8)
  • B
    4% (2)
  • C
    67% (32)
  • D
    13% (6)

Explanation

Contractual requirements and policy mandates (Choices B and D) establish what the provider should do but offer no independent verification that they actually do it. Regular reviews of the provider's own policies (Choice A) are self-assessed and lack objectivity. Independent third-party compliance audits provide objective, evidence-based verification that security controls are actually implemented and operating effectively. Because the auditor has no stake in the outcome, findings are credible and actionable. This is the most effective method because it closes the gap between what is promised and what is practiced.

Topics

#Third-party risk management#Outsourcing security#Security assurance#Compliance auditing

Community Discussion

No community discussion yet for this question.

Full CISM Practice