nerdexam
Isaca

CISM · Question #975

From a security perspective, what is the MOST important consideration when planning to leverage a Software as a Service (SaaS) provider?

The correct answer is C. Performing due diligence. Performing due diligence (C) is the most important security consideration because before entrusting a third party with your data and systems, you must thoroughly evaluate their security controls, compliance posture, data handling practices, contractual obligations, and incident…

Submitted by joshua94· Apr 18, 2026Information Security Risk Management

Question

From a security perspective, what is the MOST important consideration when planning to leverage a Software as a Service (SaaS) provider?

Options

  • APerforming regular penetration testing
  • BObtaining senior management input
  • CPerforming due diligence
  • DObtaining approval from data owners

How the community answered

(27 responses)
  • B
    4% (1)
  • C
    89% (24)
  • D
    7% (2)

Explanation

Performing due diligence (C) is the most important security consideration because before entrusting a third party with your data and systems, you must thoroughly evaluate their security controls, compliance posture, data handling practices, contractual obligations, and incident response capabilities - none of which can be corrected after the fact.

  • A (Penetration testing) is a valuable ongoing activity, but it's reactive and operational - it doesn't address whether the SaaS provider meets your security baseline before you commit to them.
  • B (Senior management input) is a governance step, not a security-specific requirement; management may be consulted, but their opinion doesn't validate the provider's security posture.
  • D (Data owner approval) matters for governance and access control, but it assumes the provider has already been vetted - approving a data transfer to an insecure provider creates risk regardless of who signed off.

Memory tip: Think of due diligence as "security homework before the first day" - just like you'd research a contractor before handing them your house keys, you must evaluate a SaaS provider before handing them your data. The other options all happen after or around that foundational step.

Topics

#SaaS security#Third-party risk management#Vendor assessment#Due diligence

Community Discussion

No community discussion yet for this question.

Full CISM Practice