Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 358 discussion

Actual exam question from Isaca's CISM
Question #: 358
Topic #: 1
[All CISM Questions]

An information security manager has been asked to provide contract guidance from a security perspective for outsourcing the organization's payroll processing
Which of the following is MOST important to address?

  • A. Vendor compliance with the most stringent data security regulations
  • B. Vendor compliance with the organization's information security policies
  • C. Vendor compliance with organizational service level agreement (SLA) requirements
  • D. Vendor compliance with recognized industry security standards
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
dark_3k03r
Highly Voted 1 year, 7 months ago
Selected Answer: B
The Correct answer is (B) Vendor compliance with the organization's information security policies. Without the vendor adhering to the organization's security policies the org's critical information is surely going to be at risk. Rationale (A) Just because the vendor is complying with the most stringent data security regulations doesn't mean that it is meeting the org's security policy as the org could have some obtuse or org-specific policy that isn't covered by the regulation. (C.)SLA don't may or may not be security related. (B) is a better answer in this case. (D) Vendor compliance with recognized industry security standards doesn't mean that it will be compliant with the ORG's security policy and posture. So as you can see the only one that truly aligns with the org's security stance is (B) Vendor compliance with the organization's information security policies.
upvoted 8 times
...
vickyguna78
Most Recent 3 months, 3 weeks ago
best answer would be compliance to PDPA or similar regulations, but if hypothetically the org have implemented controls/practices based on industry standard, B would be a great answer
upvoted 1 times
...
jcisco123
11 months ago
Selected Answer: D
The vendor complies with the organization's information security policies (option B) is important, those policies may vary from one organization to another and may not cover all security aspects that industry standards encompass. Therefore, industry security standards are often considered a more critical benchmark when outsourcing critical functions like payroll processing.
upvoted 1 times
...
King21
12 months ago
Question says 'from a security perspective' therefore answer is B. The Security Manager will not be concerned about the legal or performance stuff contained in the SLA
upvoted 1 times
...
[Removed]
1 year ago
Selected Answer: C
B could be included in C among other points
upvoted 1 times
...
richck102
1 year, 5 months ago
B. Vendor compliance with the organization's information security policies
upvoted 1 times
...
CarlPTY07
1 year, 8 months ago
Selected Answer: C
A vendor will no comply with all my Info sec regulations. that's why we create an SLA, (which are the happy medium) and from there we go!
upvoted 1 times
...
bambs
1 year, 10 months ago
Selected Answer: C
Why not C? The SLA should contain the information security policies
upvoted 1 times
Rowlandmarc
1 year, 8 months ago
Would be B as from a security perspective this would ensure they manage and treat the payroll data to the same standard. From a security perspective the service level of payroll management is not crucial (so long as the data is secure/meets policy it doesn't matter when people get paid etc)
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...