nerdexam
Isaca

CISM · Question #975

From a security perspective, what is the MOST important consideration when planning to leverage a Software as a Service (SaaS) provider?

The correct answer is C. Performing due diligence. Performing due diligence (C) is the most important security consideration because before entrusting a third party with your data and systems, you must thoroughly evaluate their security controls, compliance posture, data handling practices, contractual obligations, and incident r

Submitted by joshua94· Apr 18, 2026Information Security Risk Management

Question

From a security perspective, what is the MOST important consideration when planning to leverage a Software as a Service (SaaS) provider?

Options

  • APerforming regular penetration testing
  • BObtaining senior management input
  • CPerforming due diligence
  • DObtaining approval from data owners

How the community answered

(27 responses)
  • B
    4% (1)
  • C
    89% (24)
  • D
    7% (2)

Explanation

Performing due diligence (C) is the most important security consideration because before entrusting a third party with your data and systems, you must thoroughly evaluate their security controls, compliance posture, data handling practices, contractual obligations, and incident response capabilities - none of which can be corrected after the fact.

  • A (Penetration testing) is a valuable ongoing activity, but it's reactive and operational - it doesn't address whether the SaaS provider meets your security baseline before you commit to them.
  • B (Senior management input) is a governance step, not a security-specific requirement; management may be consulted, but their opinion doesn't validate the provider's security posture.
  • D (Data owner approval) matters for governance and access control, but it assumes the provider has already been vetted - approving a data transfer to an insecure provider creates risk regardless of who signed off.

Memory tip: Think of due diligence as "security homework before the first day" - just like you'd research a contractor before handing them your house keys, you must evaluate a SaaS provider before handing them your data. The other options all happen after or around that foundational step.

Topics

#SaaS security#Third-party risk management#Vendor assessment#Due diligence

Community Discussion

No community discussion yet for this question.

Full CISM Practice