Isaca
CISM · Question #597
Which of the following is the MOST critical activity for an information security manager to perform periodically throughout the term of a contract with an outsourced third party?
The correct answer is A. Comprehensive risk assessments. Performing periodic risk assessments is most critical to ensure that security risks introduced by the third party are continuously identified, evaluated, and managed throughout the duration of the
Submitted by certguy· Apr 18, 2026Information Security Risk Management
Question
Which of the following is the MOST critical activity for an information security manager to perform periodically throughout the term of a contract with an outsourced third party?
Options
- AComprehensive risk assessments
- BService level agreement (SLA) updates
- CParticipatory disaster recovery testing
- DFinancial alignment reviews
How the community answered
(27 responses)- A70% (19)
- B7% (2)
- C19% (5)
- D4% (1)
Explanation
Performing periodic risk assessments is most critical to ensure that security risks introduced by the third party are continuously identified, evaluated, and managed throughout the duration of the
Topics
#Third-party risk management#Vendor risk assessment#Outsourcing security#Continuous monitoring
Community Discussion
No community discussion yet for this question.