nerdexam
Isaca

CISM · Question #599

During the selection of a Software as a Service (SaaS) vendor for a business process, the vendor provides evidence of a globally accepted information security certification. Which of the following…

The correct answer is A. The certification is issued for the specific scope. The most important consideration is that the certification applies to the specific scope of services being used. A certification outside the relevant scope may not adequately cover the security of the systems or processes critical to the organization.

Submitted by mike_84· Apr 18, 2026Information Security Risk Management

Question

During the selection of a Software as a Service (SaaS) vendor for a business process, the vendor provides evidence of a globally accepted information security certification. Which of the following is the MOST important consideration?

Options

  • AThe certification is issued for the specific scope.
  • BThe certification was issued within the last five years.
  • CThe certification is easily verified.
  • DThe certification includes industry-recognized security controls.

How the community answered

(50 responses)
  • A
    52% (26)
  • B
    30% (15)
  • C
    12% (6)
  • D
    6% (3)

Explanation

The most important consideration is that the certification applies to the specific scope of services being used. A certification outside the relevant scope may not adequately cover the security of the systems or processes critical to the organization.

Topics

#Third-party risk management#Vendor security assessment#SaaS security#Certification scope

Community Discussion

No community discussion yet for this question.

Full CISM Practice