nerdexam
Isaca

CISM · Question #597

Which of the following is the MOST critical activity for an information security manager to perform periodically throughout the term of a contract with an outsourced third party?

The correct answer is A. Comprehensive risk assessments. Performing periodic risk assessments is most critical to ensure that security risks introduced by the third party are continuously identified, evaluated, and managed throughout the duration of the

Submitted by certguy· Apr 18, 2026Information Security Risk Management

Question

Which of the following is the MOST critical activity for an information security manager to perform periodically throughout the term of a contract with an outsourced third party?

Options

  • AComprehensive risk assessments
  • BService level agreement (SLA) updates
  • CParticipatory disaster recovery testing
  • DFinancial alignment reviews

How the community answered

(27 responses)
  • A
    70% (19)
  • B
    7% (2)
  • C
    19% (5)
  • D
    4% (1)

Explanation

Performing periodic risk assessments is most critical to ensure that security risks introduced by the third party are continuously identified, evaluated, and managed throughout the duration of the

Topics

#Third-party risk management#Vendor risk assessment#Outsourcing security#Continuous monitoring

Community Discussion

No community discussion yet for this question.

Full CISM Practice