exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 87 discussion

Actual exam question from Isaca's CISM
Question #: 87
Topic #: 1
[All CISM Questions]

Which of the following BEST provides an information security manager with sufficient assurance that a service provider complies with the organization's information security requirements?

  • A. A live demonstration of the third-party supplier's security capabilities
  • B. The ability to audit the third-party supplier's IT systems and processes
  • C. Third-party security control self-assessment results
  • D. An independent review report indicating compliance with industry standards
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AaronS1990
Highly Voted 1 year, 5 months ago
Selected Answer: B
I still like B. It’s a close one but ISACA love right to audit clauses and D checks against industry standards and not your organisation’s standards. B
upvoted 7 times
...
Josef4CISM
Highly Voted 5 months, 3 weeks ago
B, because the question asks about the compliance of the ORGANIZATIONS security requirements. You can only check compliance by auditing the third party yourself, as industry best practices / frameworks (answer D) may contain different security requirements in comparison to the requirements from the security managers organization.
upvoted 5 times
...
Az900500
Most Recent 3 weeks ago
Selected Answer: B
The BEST option for assurance is B. The ability to audit the third-party supplier's IT systems and processes. Direct audit rights provide the highest level of assurance. It allows the organization to independently verify the service provider's security controls and their effectiveness. This is far more reliable than relying on self-assessments or even third-party reports, as it gives the organization direct evidence.
upvoted 1 times
...
GAAMMC
4 weeks, 1 day ago
Selected Answer: B
The right to audit will provide this assurance
upvoted 1 times
...
grandMa
4 months, 1 week ago
Selected Answer: B
The answer is B unless the third party satisfies the security requirements of the client organization, the business infosec requirements might not be fully satisfied by the industry standards only.
upvoted 2 times
...
alifjouj
6 months ago
Selected Answer: D
an independent review report is itself an audit
upvoted 2 times
GAAMMC
4 weeks, 1 day ago
Not against industry best practice, It has to be against the companies IS policies etc
upvoted 1 times
...
...
bcffcfb
7 months, 3 weeks ago
D: An independent review report, such as a SOC 2 Type II report, ISO 27001 certification, or similar, is conducted by external auditors and provides an objective assessment of the service provider’s compliance with established industry standards. These reports are typically comprehensive, include testing of controls over a period of time, and provide a higher level of assurance due to their independence and adherence to strict auditing standards.
upvoted 1 times
Noragretz
1 month, 1 week ago
But this doesn’t mean it meets your organizations standard for your particular area of business or country or locality.
upvoted 1 times
...
...
Eltooth
8 months, 3 weeks ago
Selected Answer: D
This is a tough one - going with D as correct answer. Ability to audit does not mean that an audit has actually taken place to confirm that supplier standards meet the needs of the company. Therefore no actual output to measure against company standards. An independent audit against industry standard shows an outcome that can be measured against the company standards - however there is no guarantee the industry standard meets the company requirements.
upvoted 3 times
...
helg420
9 months, 3 weeks ago
Selected Answer: B
B. The ability to audit the third-party supplier's IT systems and processes Having the ability to conduct audits on the third-party supplier's IT systems and processes allows the information security manager to directly assess and verify compliance with the organization’s specific information security requirements. This direct approach enables the organization to pinpoint areas of concern, ask specific questions, and receive immediate clarification or evidence of compliance that aligns with their unique requirements, rather than relying solely on general industry standards. This option ensures a more nuanced and tailored evaluation of the supplier's adherence to the specific security policies, controls, and standards expected by the hiring organization.
upvoted 1 times
...
03allen
10 months, 1 week ago
Selected Answer: D
I choose D. industry compliance certificate like SOC2 will indicate the vendor offers a reliable service. We all know, the organization will not have time to audit vendor IT infrastructure by themself, and the vendor will not allow them to as well.
upvoted 2 times
...
oluchecpoint
1 year ago
Selected Answer: D
D. An independent review report indicating compliance with industry standards An independent review report indicating compliance with industry standards is often a reliable source of assurance because it means that the service provider's practices have been evaluated by an independent third party against recognized industry standards or frameworks. These independent reviews are typically conducted by reputable audit or certification bodies.
upvoted 3 times
...
Uncle_Lucifer
1 year, 2 months ago
Selected Answer: B
D would have been best if it focused on the org's policy and not industry standard. B is better answer for the question.
upvoted 3 times
...
Cyberbug2021
1 year, 3 months ago
Selected Answer: D
organizations have a hard time auditing themselves and dealing with their own audits, let alone be able to audit a vendor, plus a vendor won't let you.
upvoted 2 times
...
Viperhunter
1 year, 3 months ago
Selected Answer: D
An independent review report, especially one indicating compliance with recognized industry standards, provides a level of assurance about the service provider's adherence to established security practices. Independent assessments, audits, or certifications conducted by reputable third-party organizations can verify the effectiveness of a service provider's security controls and processes. While a live demonstration (Option A) may provide some insight, it may not cover all aspects of security, and it may not be as thorough as an independent review. The ability to audit the third-party supplier's IT systems and processes (Option B) is a strong option, but it may not always be feasible due to legal or contractual constraints. Third-party security control self-assessment results (Option C) may lack the objectivity and independence provided by external assessments. Therefore, an independent review aligned with industry standards is often considered a robust assurance mechanism.
upvoted 2 times
...
Perseus_68
1 year, 4 months ago
Are the correct answers displayed really correct or do they wait for the community to define the answer? the "right" to audit has NO assurance that a service provider complies with the organization's IS Program. No proof has been established until evidence (like a third-party report) or the audit has been performed, or a security review has been performed.
upvoted 1 times
...
sphenixfire
1 year, 5 months ago
Selected Answer: B
not D because check the requirements you set, not the standards. B because the "right to audit"
upvoted 2 times
...
oluchecpoint
1 year, 6 months ago
D. An independent review report indicating compliance with industry standards An independent review report indicating compliance with industry standards is often a reliable source of assurance because it means that the service provider's practices have been evaluated by an independent third party against recognized industry standards or frameworks. These independent reviews are typically conducted by reputable audit or certification bodies.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago