Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 323 discussion

Actual exam question from Isaca's CISM
Question #: 323
Topic #: 1
[All CISM Questions]

What is the role of the information security manager in finalizing contract negotiations with service providers?

  • A. To perform a risk analysis on the outsourcing process
  • B. To obtain a security standard certification from the provider
  • C. To update security standards for the outsourced process
  • D. To ensure that clauses for periodic audits are included
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
david124
1 week, 3 days ago
Selected Answer: A
A my dawg
upvoted 1 times
...
Marcelus1714
7 months, 3 weeks ago
Selected Answer: A
I would go for A...
upvoted 1 times
...
yottabyte
8 months ago
Selected Answer: D
D. To ensure that clauses for periodic audits are included
upvoted 1 times
...
Soleandheel
12 months ago
Again i can see people just blindly going with Chatgpt lol. If you go with Chatgpt, Chatgpt initially said the correct answer is D. To ensure that clauses for periodic audits are included. However, when i explained the following to it, it changed it's answer and agreed with me: A. To perform a risk analysis on the outsourcing process is the correct answer i think. Ensuring that clauses for periodic audits are included during contract negotiation is in a sense part of performing risk analysis on the outsourcing process. A. is the better answer in my opinion. Chatgpt changed it's mind and agreed with me that A. To perform a risk analysis on the outsourcing process is the best answer. Keep in mind that the risk analysis encompasses the ensurance of clauses for periodic audits.
upvoted 3 times
Raven89
2 weeks, 6 days ago
i agree with you. STOP using chatGPT, study and use your brain. Even for me the correct answer is A.
upvoted 1 times
...
...
oluchecpoint
1 year, 2 months ago
A. To perform a risk analysis on the outsourcing process While all the options may play a role in contract negotiations with service providers, performing a risk analysis on the outsourcing process is crucial. Information security managers need to assess the potential risks and security implications associated with outsourcing specific services or processes to third-party providers. This involves identifying potential vulnerabilities, evaluating the security measures in place at the service provider's end, and ensuring that the contract includes provisions to mitigate identified risks. The other options, while important, are not typically the primary responsibilities of the information security manager during contract negotiations
upvoted 2 times
...
DASH_v
1 year, 5 months ago
Selected Answer: A
what if the service provider is not critical in terms of information security, e.g. a maintenance service for office cooling system, so why D? As a IS manager, action always guided by the risk, i.e. risk based approach, so A.
upvoted 2 times
[Removed]
1 year, 4 months ago
Risk Assessment is done before finalizing the contract. At the business case
upvoted 2 times
...
...
wello
1 year, 5 months ago
Selected Answer: D
at the final stage of the contract we make sure the periodic audit clause is included.
upvoted 3 times
...
richck102
1 year, 5 months ago
D. To ensure that clauses for periodic audits are included
upvoted 2 times
...
cheesesteak
1 year, 7 months ago
Selected Answer: D
D. To ensure that clauses for periodic audits are included. The information security manager is responsible for ensuring that the contract with the service provider includes appropriate security measures to protect the organization's information assets. This may include clauses that require the service provider to undergo periodic security audits to ensure compliance with security standards, policies, and procedures. The information security manager may also work with legal and procurement teams to negotiate and include relevant security clauses in the contract to protect the organization's interests. Additionally, the information security manager may collaborate with other stakeholders to perform a risk analysis on the outsourcing process, obtain security standard certifications from the provider, and update security standards for the outsourced process as needed. However, ensuring that clauses for periodic audits are included is a key responsibility of the information security manager in contract negotiations with service providers to ensure that security requirements are met and maintained throughout the duration of the contract.
upvoted 3 times
...
cosmo4ng
1 year, 8 months ago
Selected Answer: D
Ii go with D
upvoted 2 times
...
CarlPTY07
1 year, 8 months ago
Selected Answer: D
Negotiation is finalizing, all done..just check for the contract details.
upvoted 4 times
...
jaiz
1 year, 8 months ago
Selected Answer: D
We are performing analysis during contract negotiation. Ensure important clause is more relevant. D is the correct answer in the context of contract negotiation.
upvoted 1 times
...
Rowlandmarc
1 year, 8 months ago
pretty poor question... in finalising the agreement none of these are ideal in the last few stages....
upvoted 2 times
...
N1co_o
1 year, 8 months ago
Selected Answer: A
A i guess
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...