nerdexam
Isaca

CISM · Question #930

A third-party vendor is developing a mobile app for an organization's customers. Which of the following issues should be of GREATEST concern to the information security manager?

The correct answer is D. The contract has no data security requirements. Without data security requirements in the contract, the organization has no enforceable obligations for how customer data will be protected (controls, breach notification, privacy requirements, testing, retention, etc.), creating the greatest and most immediate third-party risk.

Submitted by femi9· Apr 18, 2026Information Security Risk Management

Question

A third-party vendor is developing a mobile app for an organization's customers. Which of the following issues should be of GREATEST concern to the information security manager?

Options

  • AService level agreements (SLAs) after deployment are not defined.
  • BThe mobile app's programmers are all offshore contractors.
  • CThe vendor subcontracts its information security functions.
  • DThe contract has no data security requirements.

How the community answered

(34 responses)
  • A
    9% (3)
  • B
    35% (12)
  • C
    15% (5)
  • D
    41% (14)

Explanation

Without data security requirements in the contract, the organization has no enforceable obligations for how customer data will be protected (controls, breach notification, privacy requirements, testing, retention, etc.), creating the greatest and most immediate third-party risk.

Topics

#Third-party risk management#Contractual security#Vendor security#Data security requirements

Community Discussion

No community discussion yet for this question.

Full CISM Practice