Courseiva

CISM Information Security Programme Practice Question

A CISO is establishing a vendor risk management (TPRM) program. Which THREE of the following are key components of an effective TPRM program?

⚠ Common exam trap

CISM often tests the principle of risk-based vendor management; candidates may pick 'all vendors must be ISO 27001 certified' because it sounds rigorous, but the exam expects recognition that a one-size-fits-all requirement is not effective TPRM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exit procedures to ensure data is returned or destroyed.

Option A is correct because an effective TPRM program must define exit procedures that ensure vendor-held data is returned or securely destroyed when the relationship ends, addressing data retention and offboarding risk. Option C is correct because onboarding risk assessments should be risk-tiered, scoped to the vendor's criticality and level of access to systems and data, rather than applying uniform treatment. Option E is correct because vendor risk is continuous, so ongoing monitoring of the vendor's security posture (for example, via security ratings, questionnaires, or attestation tracking) is needed to detect changes after onboarding. Option B is not appropriate because a single annual assessment for all vendors ignores differing risk levels and fails to provide continuous oversight. Option D is not required because ISO 27001 certification is only one possible assurance mechanism; mandating it for all vendors is overly prescriptive and does not fit a risk-based program.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Exit procedures to ensure data is returned or destroyed.

    Why this is correct

    Exit procedures guarantee that vendor-held data is returned or securely destroyed when the relationship ends, closing the offboarding gap where residual data exposure persists. This satisfies the stem's requirement for a key TPRM component by addressing the full vendor lifecycle, not just onboarding.

  • ✗

    Performing a single annual assessment for all vendors.

    Why it's wrong here

    A single annual assessment for all vendors ignores differing risk tiers, so critical suppliers receive the same scrutiny as low-risk ones and emerging risks go undetected between cycles. It is tempting because it standardises effort and simplifies scheduling, but effective TPRM requires risk-based, continuous monitoring.

  • ✓

    Onboarding risk assessment based on vendor criticality and data access.

    Why this is correct

    Risk-tiering at onboarding directs deeper due diligence toward vendors handling sensitive data or supporting critical functions, rather than applying uniform scrutiny. This satisfies the stem's requirement for a key TPRM component by ensuring assessment effort is proportionate to inherent vendor risk and data access.

  • ✗

    Requiring all vendors to have ISO 27001 certification.

    Why it's wrong here

    Certification mandates exclude capable vendors and assess documentation, not the risk each engagement creates; TPRM tiers vendors by data sensitivity and access. ISO 27001 suits organisations seeking assurance of a vendor's security management system, but it cannot replace ongoing due diligence, contractual controls and continuous monitoring.

  • ✓

    Ongoing monitoring of vendor security posture.

    Why this is correct

    Continuous monitoring detects posture changes, new vulnerabilities and breaches after onboarding, since a vendor's risk profile is not static. This satisfies the stem's requirement for a key TPRM component by maintaining assurance throughout the relationship rather than relying solely on a point-in-time assessment.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.