Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 825 discussion

Actual exam question from Isaca's CISM
Question #: 825
Topic #: 1
[All CISM Questions]

Which of the following is the BEST way to assess the risk associated with using a Software as a Service (SaaS) vendor?

  • A. Require vendors to complete information security questionnaires.
  • B. Request customer references from the vendor.
  • C. Verify that information security requirements are included in the contract.
  • D. Review the results of the vendor's independent control reports.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Pabl0T0rrez
Highly Voted 1 year, 6 months ago
D? The best way to assess the risk associated with using a Software as a Service (SaaS) vendor is to review the results of the vendor's independent control reports. This will help you to understand the vendor's security practices and procedures, and to identify any potential risks.
upvoted 9 times
Soleandheel
12 months ago
Yes correct!
upvoted 1 times
...
DERCHEF2009
1 year, 5 months ago
agree with you
upvoted 2 times
...
Jae_kes
1 year, 5 months ago
Correct
upvoted 1 times
...
...
Booict
Most Recent 3 months, 3 weeks ago
Selected Answer: D
D - provide concrete evidence of the vendor’s compliance with security standards and their effectiveness in managing security risks.
upvoted 1 times
...
maisarajarrah
10 months, 1 week ago
Selected Answer: D
The BEST way to assess the risk associated with using a Software as a Service (SaaS) vendor is option D: "Review the results of the vendor's independent control reports." Independent control reports, such as SOC 2 (Service Organization Control 2) reports, provide detailed information about a vendor's security controls and practices. These reports are typically issued by third-party auditors and can give you valuable insights into the effectiveness of the vendor's security measures.
upvoted 1 times
...
Soleandheel
12 months ago
D. Review the results of the vendor's independent control reports. SOC 2 reports are examples of a vendor's independent control report. These reports can help you assess the risk associated with a SaaS provider.
upvoted 1 times
Soleandheel
12 months ago
SOC 2 reports are done by independent auditors so they tend to be reliable.
upvoted 1 times
...
...
Marcovic00
12 months ago
Selected Answer: D
assess the risk is D
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: D
Reviewing the results of the vendor's independent control reports is the best approach because it involves assessing the vendor's security controls and practices through an independent, third-party audit or assessment. These reports, such as SOC 2 (System and Organization Controls) reports, provide detailed information about the effectiveness of the vendor's security controls and can give you a more objective view of their security posture.
upvoted 1 times
...
iacini
1 year, 2 months ago
Selected Answer: A
Definitely A, how you can rely on ISO 27001 if you are choosing someone to process CID in financial institution? You need to have your own questionnaires and this is the best option.
upvoted 1 times
...
AXL1
1 year, 3 months ago
Hi Guys, what is Isaca (formal) response to this question ? is it the one in green ? I don't understand how this site works.
upvoted 1 times
...
J1984
1 year, 4 months ago
The BEST way to "assess" the risk of a third-party is: A. Require vendors to complete information security questionnaires. Questionnaires provide current information relative to security requirements that important to your organization. Independent control reports may not be as timely or as current and do not necessarily reflect the risks most important your organization.
upvoted 2 times
Marcelus1714
9 months, 1 week ago
you can put whatever you want in the answers of a questionnaire. But if an independent organization is assessing I guess is BEST
upvoted 1 times
...
...
koala_lay
1 year, 4 months ago
Selected Answer: D
The best way to assess the risk associated with using a Software as a Service (SaaS) vendor is to review the results of the vendor's independent control reports. This will provide the most comprehensive assessment of the vendor's security controls, giving you a better understanding of the risks associated with the vendor.
upvoted 2 times
...
richck102
1 year, 4 months ago
D. Review the results of the vendor's independent control reports.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...