exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 147 discussion

Actual exam question from Isaca's CISM
Question #: 147
Topic #: 1
[All CISM Questions]

Which of the following is MOST important to include in a contract with a critical service provider to help ensure alignment with the organization's information security program?

  • A. Escalation paths
  • B. Termination language
  • C. Key performance indicators (KPIs)
  • D. Right-to-audit clause
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
afb4b17
1 month, 2 weeks ago
the key words are " to help ensure alignment". This is done by KPI's.
upvoted 1 times
...
helg420
2 months ago
Selected Answer: D
D. Right-to-audit clause Including a right-to-audit clause in your contract with a critical service provider is crucial for maintaining transparency and verifying compliance with the organization's information security standards. This clause grants the organization the authority to conduct audits or assessments of the vendor’s practices, procedures, and performance to ensure they adhere to the agreed-upon terms and conditions, particularly those related to information security. This capability is vital for detecting and addressing potential security vulnerabilities, ensuring that the service provider's security measures align with the organization's requirements, and safeguarding sensitive information.
upvoted 1 times
...
Chaser
2 months, 1 week ago
Part of me Feels D would be right if this was the CISA exam but is C for this.
upvoted 1 times
...
Marcelus1714
4 months, 1 week ago
Selected Answer: D
Do you put KPIs in a contract?!? what you should put is SLAs, right? but KPIs!? I would go for D
upvoted 2 times
...
Manix
5 months, 3 weeks ago
Selected Answer: C
3.13.2 managing inf risk on day to day basis -> KP|
upvoted 1 times
...
sphenixfire
10 months, 1 week ago
Selected Answer: D
Right to audit
upvoted 2 times
...
oluchecpoint
10 months, 2 weeks ago
D. A right-to-audit clause allows the organization to conduct periodic audits or assessments of the service provider's security practices, processes, and compliance with the terms of the contract. This is crucial for maintaining visibility into the security measures and practices of the service provider, ensuring that they are in line with the organization's information security program, and verifying that the service provider is meeting agreed-upon security standards and requirements.
upvoted 1 times
...
todush
11 months, 1 week ago
KPIs as an objective : yes. KPIa an an outcome : no.
upvoted 1 times
...
richck102
1 year, 1 month ago
C. Key performance indicators (KPIs)
upvoted 1 times
richck102
1 year, 1 month ago
D. Right-to-audit clause
upvoted 1 times
...
...
Abhey
1 year, 2 months ago
Selected Answer: D
A "Right-to-audit clause" is the MOST important to include in a contract with a critical service provider to help ensure alignment with the organization's information security program. This clause allows the organization to conduct audits on the provider's security controls, processes, and policies to ensure that they meet the organization's requirements and standards. By including this clause, the organization can monitor the provider's security posture and address any identified security issues before they become a significant risk to the organization.
upvoted 1 times
...
jaiz
1 year, 4 months ago
Selected Answer: C
D is not the most important. Sometime small business does not have right to audit public cloud. So KPI or SLA is the MOST important.
upvoted 4 times
Marcelus1714
4 months, 1 week ago
I believe here is the problem of this question, if I see "SLA" I select C, if I see KPI i go for D...
upvoted 1 times
...
...
giovi
1 year, 4 months ago
Selected Answer: D
Naturally is D
upvoted 1 times
...
vavofa5697
1 year, 5 months ago
Selected Answer: D
KPI is incorrect it should be SLA instead. So the best answer is D.
upvoted 1 times
...
Broesweelies
1 year, 5 months ago
Selected Answer: D
A right-to-audit clause in a contract with a critical service provider is important to include in order to ensure alignment with the organization's information security program. This clause gives the organization the ability to conduct audits on the service provider's security practices and ensure that they are meeting the standards and requirements set forth in the contract. This can help to identify any potential security risks or vulnerabilities and take steps to address them before they can cause harm to the organization. The other options are also important to include, but are not as critical to ensure alignment with the organization's information security program.
upvoted 4 times
vavofa5697
1 year, 5 months ago
agreed
upvoted 1 times
...
...
baranikumar_v
1 year, 6 months ago
D. Right-to-audit
upvoted 2 times
...
aokisan
1 year, 6 months ago
Selected Answer: D
Clearly, D.
upvoted 1 times
...
Ziggybooboo
1 year, 7 months ago
D I think
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago