Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 516 discussion

Actual exam question from Isaca's CISM
Question #: 516
Topic #: 1
[All CISM Questions]

An organization has outsourced many application development activities to a third party that uses contract programmers extensively. Which of the following would provide the BEST assurance that the third party's contract programmers comply with the organization's security policies?

  • A. Perform periodic security assessments of the contractors' activities.
  • B. Conduct periodic vulnerability scans of the application.
  • C. Require annual signed agreements of adherence to security policies.
  • D. Include penalties for noncompliance in the contracting agreement.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
david124
3 weeks, 2 days ago
Selected Answer: C
How the hell is it A? Since when you can monitor 3rd party companies let alone their contractors? I think C here
upvoted 2 times
...
richck102
1 year, 4 months ago
A. Perform periodic security assessments of the contractors' activities.
upvoted 1 times
...
Saisharan
1 year, 5 months ago
Option A
upvoted 1 times
...
Souvik124
1 year, 9 months ago
Performing periodic security assessments of the contractors' activities would provide the BEST assurance that the third party's contract programmers comply with the organization's security policies. This approach will enable the organization to evaluate the security controls and procedures implemented by the third-party and assess their effectiveness in complying with the organization's security policies. By conducting security assessments, the organization will be able to identify any vulnerabilities, gaps, or weaknesses in the third-party's security posture and recommend remediation measures. This will help to ensure that the third-party's contract programmers comply with the organization's security policies and that the organization's information assets are adequately protected.
upvoted 2 times
...
Broesweelies
1 year, 9 months ago
Selected Answer: A
A. Perform periodic security assessments of the contractors' activities would provide the best assurance that the third party's contract programmers comply with the organization's security policies. This is because security assessments involve a thorough review of the contractors' activities, including their development processes, tools and methodologies, as well as the security controls they have implemented. This will allow the organization to identify any potential vulnerabilities or noncompliance issues and address them proactively. While the other options such as conducting periodic vulnerability scans, requiring annual signed agreements, and including penalties for noncompliance in the contracting agreement, are also important and can help to ensure compliance, they are not as comprehensive as security assessments, and may not provide the same level of assurance.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...