exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 239 discussion

Actual exam question from Isaca's CISM
Question #: 239
Topic #: 1
[All CISM Questions]

Which of the following BEST indicates the effectiveness of the vendor risk management process?

  • A. Increase in the percentage of vendors certified to a globally recognized security standard
  • B. Increase in the percentage of vendors with a completed due diligence review
  • C. Increase in the percentage of vendors conducting mandatory security training
  • D. Increase in the percentage of vendors that have reported security breaches
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Broesweelies
Highly Voted 2 years ago
Selected Answer: B
The best indicator of the effectiveness of the vendor risk management process is an increase in the percentage of vendors that have completed a due diligence review. Due diligence review is an important aspect of vendor risk management. It involves evaluating a vendor's security practices, policies, and controls, as well as assessing their overall risk profile. By conducting thorough due diligence reviews, organizations can identify and mitigate potential risks associated with using a particular vendor.
upvoted 5 times
...
sursur
Most Recent 10 months ago
Selected Answer: B
An effective vendor risk management plan is characterized by its vendor due diligence policy. Vendor onboarding is one of the most delicate phases of a VRM program because it has a significant impact on an organization’s security posture. Poor onboarding practices will overlook the different types of risks and security vulnerabilities of new vendors, adding these risk to your risk profile. "https://www.upguard.com/blog/vendor-risk-management#:~:text=Vendor%20risk%20management%20is%20an,compliance%2C%20legal%20and%20regulatory%20risks."
upvoted 1 times
...
oluchecpoint
12 months ago
Selected Answer: B
Option B
upvoted 1 times
...
killainc
1 year, 1 month ago
The best indicator of the effectiveness of the vendor risk management process is an increase in the percentage of vendors with a completed due diligence review. This suggests that the organization is actively assessing and evaluating the risks associated with its vendors, which is a fundamental aspect of effective vendor risk management. Completing due diligence reviews helps ensure that vendors are meeting security and compliance requirements, reducing potential risks to the organization.
upvoted 1 times
...
Learner76
1 year, 1 month ago
Selected Answer: B
B - D could be a case of bad vendors selection
upvoted 1 times
...
XJ
1 year, 2 months ago
B - https://vendorcentric.com/single-post/vendor-due-diligence-reviews-an-important-tool-for-mitigating-risk/#:~:text=Vendor%20due%20diligence%20is%20a%20business%20discipline%20used,ethically%20sound%20and%20has%20an%20effective%20corporate%20structure.
upvoted 1 times
...
karanvp
1 year, 7 months ago
D is the correct answer. Because if more breaches reported for the vendor, then can say that vendor not effectively manage their security programs.
upvoted 1 times
...
wello
1 year, 7 months ago
Selected Answer: D
option D, an increase in the percentage of vendors that have reported security breaches, suggests that the vendor risk management process is effectively identifying and capturing security incidents or breaches experienced by vendors. This indicates that the process has mechanisms in place to detect and respond to security issues, enabling timely remediation actions to be taken.
upvoted 2 times
...
richck102
1 year, 7 months ago
B. Increase in the percentage of vendors with a completed due diligence review
upvoted 1 times
...
CarlPTY07
1 year, 10 months ago
Selected Answer: B
Clearly B
upvoted 4 times
...
CarlPTY07
1 year, 10 months ago
Selected Answer: B
This is the best indicator. Since you already made sure all the controls and requirements are met.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...