nerdexam
Isaca

CISM · Question #691

Which of the following is the BEST way to help ensure third-party vendors maintain adequate information security controls to protect the organization's assets?

The correct answer is A. Engage independent security audits. Independent security audits provide the most reliable assurance that third-party vendors maintain adequate security controls, as they offer objective verification beyond self-assessments or contractual agreements.

Submitted by andres_qro· Apr 18, 2026Information Security Risk Management

Question

Which of the following is the BEST way to help ensure third-party vendors maintain adequate information security controls to protect the organization’s assets?

Options

  • AEngage independent security audits.
  • BRequire vendors to complete security questionnaires.
  • CImplement vendor security policy reviews.
  • DEstablish service level agreements (SLAs).

How the community answered

(37 responses)
  • A
    62% (23)
  • B
    22% (8)
  • C
    5% (2)
  • D
    11% (4)

Explanation

Independent security audits provide the most reliable assurance that third-party vendors maintain adequate security controls, as they offer objective verification beyond self-assessments or contractual agreements.

Topics

#Vendor Risk Management#Third-Party Security#Security Audits#Information Security Assurance

Community Discussion

No community discussion yet for this question.

Full CISM Practice