nerdexam
Isaca

CISM · Question #816

An outsourced vendor handles an organization's business-critical data. Which of the following is the MOST effective way for the client organization to obtain assurance of the vendor's security practic

The correct answer is D. Requiring periodic independent third-party reviews. Periodic independent third-party reviews (e.g., SOC 2 Type II audits, ISO 27001 certifications) provide objective, evidence-based assurance of the vendor's actual security controls - not just what the vendor claims. Vendor-provided disclosures (A) are self-reported and potentiall

Submitted by certguy· Apr 18, 2026Information Security Risk Management

Question

An outsourced vendor handles an organization's business-critical data. Which of the following is the MOST effective way for the client organization to obtain assurance of the vendor's security practices?

Options

  • AReviewing recent information security disclosures from the vendor
  • BReviewing the vendor service level agreement (SLA)
  • CRequiring business continuity plans (BCPs) from the vendor
  • DRequiring periodic independent third-party reviews

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    13% (3)
  • C
    26% (6)
  • D
    57% (13)

Explanation

Periodic independent third-party reviews (e.g., SOC 2 Type II audits, ISO 27001 certifications) provide objective, evidence-based assurance of the vendor's actual security controls - not just what the vendor claims. Vendor-provided disclosures (A) are self-reported and potentially biased. SLAs (B) define service targets but do not validate security control effectiveness. BCPs (C) address continuity but only cover one aspect of security. Independent reviews give the broadest, most credible assurance across all security domains.

Topics

#Vendor management#Security assurance#Third-party risk#Independent audit

Community Discussion

No community discussion yet for this question.

Full CISM Practice