nerdexam
(ISC)2

CISSP · Question #393

Which of the following four iterative steps are conducted on third-party vendors in an on-going basis?

The correct answer is B. Frame, Assess, Respond, Monitor. NIST SP 800-39 defines a four-step iterative risk management process: Frame, Assess, Respond, and Monitor, which applies to third-party vendor risk management on an ongoing basis.

Submitted by viktor_hu· Mar 5, 2026Security and Risk Management

Question

Which of the following four iterative steps are conducted on third-party vendors in an on-going basis?

Options

  • AInvestigate, Evaluate, Respond, Monitor
  • BFrame, Assess, Respond, Monitor
  • CFrame, Assess, Remediate, Monitor
  • DInvestigate, Assess, Remediate, Monitor

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    90% (28)
  • C
    6% (2)

Why each option

NIST SP 800-39 defines a four-step iterative risk management process: Frame, Assess, Respond, and Monitor, which applies to third-party vendor risk management on an ongoing basis.

AInvestigate, Evaluate, Respond, Monitor

Investigate is not a defined step in the NIST SP 800-39 risk management framework; it replaces 'Frame,' which is the correct first step that establishes the risk context and strategy.

BFrame, Assess, Respond, MonitorCorrect

NIST SP 800-39 establishes the four iterative steps of risk management as Frame (establish context and risk assumptions), Assess (identify and evaluate risks), Respond (develop and implement risk response strategies), and Monitor (continuously track risk over time). This framework is applied on an ongoing basis to third-party vendors to ensure continuous risk oversight throughout the vendor relationship lifecycle.

CFrame, Assess, Remediate, Monitor

Remediate is not an official step in the NIST SP 800-39 framework; the correct third step is 'Respond,' which encompasses a broader set of actions including acceptance, avoidance, mitigation, and transfer of risk.

DInvestigate, Assess, Remediate, Monitor

This option incorrectly combines 'Investigate' in place of 'Frame' and 'Remediate' in place of 'Respond,' neither of which are recognized steps in the NIST SP 800-39 iterative risk management process.

Concept tested: NIST SP 800-39 iterative third-party risk management steps

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf

Topics

#Third-party risk management#Vendor assessment#Risk management framework#Continuous monitoring

Community Discussion

No community discussion yet for this question.

Full CISSP Practice