nerdexam
Isaca

CISM · Question #478

Which of the following is the BEST method for minimizing the risk of noncompliance to security requirements by a third-party service provider?

The correct answer is B. Periodic reviews. The best method for minimizing the risk of noncompliance by a third-party service provider is to conduct periodic reviews. These reviews help ensure that the provider continues to meet security requirements, contractual obligations, and regulatory standards over time. While…

Submitted by yaw92· Apr 18, 2026Information Security Risk Management

Question

Which of the following is the BEST method for minimizing the risk of noncompliance to security requirements by a third-party service provider?

Options

  • AUnderstanding the third-party security programs
  • BPeriodic reviews
  • CBusiness impact analysis (BIA)
  • DClear communication of security requirements

How the community answered

(21 responses)
  • A
    10% (2)
  • B
    62% (13)
  • C
    24% (5)
  • D
    5% (1)

Explanation

The best method for minimizing the risk of noncompliance by a third-party service provider is to conduct periodic reviews. These reviews help ensure that the provider continues to meet security requirements, contractual obligations, and regulatory standards over time. While understanding their security programs and communicating requirements are important, ongoing reviews provide proactive assurance that controls are maintained and risks are managed effectively. A BIA focuses on business impact rather than compliance enforcement.

Topics

#Third-party risk management#Vendor security#Compliance monitoring#Security assurance

Community Discussion

No community discussion yet for this question.

Full CISM Practice