nerdexam
Isaca

CISM · Question #86

An organization learns that a third party has outsourced critical functions to another external provider. Which of the following is the information security manager's MOST important course of action?

The correct answer is D. Evaluate the third party's agreements with its external provider.. When a third party subcontracts critical functions, the information security manager must primarily evaluate the terms of the third party's agreements with its sub-provider to ensure adequate security and compliance.

Submitted by fatima_kr· Apr 18, 2026Information Security Risk Management

Question

An organization learns that a third party has outsourced critical functions to another external provider. Which of the following is the information security manager's MOST important course of action?

Options

  • AEngage an independent audit of the third party's external provider.
  • BConduct an external audit of the contracted third party.
  • CRecommend canceling the contract with the third party.
  • DEvaluate the third party's agreements with its external provider.

How the community answered

(43 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    9% (4)
  • D
    81% (35)

Why each option

When a third party subcontracts critical functions, the information security manager must primarily evaluate the terms of the third party's agreements with its sub-provider to ensure adequate security and compliance.

AEngage an independent audit of the third party's external provider.

Engaging an independent audit of the sub-provider might be a later step, but the most important initial action is to understand the contractual obligations and existing controls.

BConduct an external audit of the contracted third party.

An external audit of the contracted third party would address their controls, but it doesn't directly address the new risk introduced by their sub-contracting of critical functions.

CRecommend canceling the contract with the third party.

Recommending canceling the contract is an extreme measure without first understanding the implications and contractual obligations of the sub-contracting.

DEvaluate the third party's agreements with its external provider.Correct

Evaluating the third party's agreements with its external provider is crucial because it ensures that the original security and compliance requirements stipulated in the primary contract are flowed down and appropriately addressed by the sub-contractor. This due diligence ensures the organization's risks are managed even through multi-tiered outsourcing.

Concept tested: Third-party risk management and sub-contractor oversight

Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final

Topics

#Third-party risk management#Fourth-party risk#Vendor agreements#Supply chain security

Community Discussion

No community discussion yet for this question.

Full CISM Practice