Answer is C: Integrate risk management into the vendor management process.
Because it provides a comprehensive, strategic approach to managing third-party security risks, fully aligned with CISM’s risk-based governance model.
leaning towards C. by integrating risk management into the vendor management process, you proactively define and shape security requirements for vendors upfront. That's a more effective way than doing security reviews and following up with deviations from time to time.
B - Auditing vendors helps evaluate their security posture, identify vulnerabilities, and ensure compliance with organizational standards. The term “audit” is more commonly associated with thorough assessments.
This section is not available anymore. Please use the main Exam Page.CISM Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
SHERLOCKAWS
1 week, 4 days agoJosef4CISM
2 months, 2 weeks agoafoo1314
7 months, 2 weeks agoBooict
8 months, 3 weeks agooluchecpoint
11 months, 2 weeks agohelg420
10 months, 3 weeks agossdny
1 year ago