Courseiva

CISM Information Security Programme Practice Question

A company is implementing a third-party risk management program and needs to prioritize vendors for assessment. Which factor should be given the highest weight?

⚠ Common exam trap

CISM often tests the misconception that financial or relationship factors (contract value, duration, vendor size) are primary risk indicators, when in fact data access and service criticality are the core determinants of third-party risk exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data access level and service criticality

The highest-weighted factor in third-party risk prioritization is the combination of data access level and service criticality. This is because risk exposure is directly proportional to the sensitivity of data the vendor can access and how essential the vendor's service is to business operations. A vendor with access to regulated data (e.g., PII, PHI) or that supports a critical business function poses a significantly higher risk if compromised, regardless of contract value or vendor size. Thus, these two dimensions determine the potential impact of a vendor-related incident, making them the primary drivers for assessment prioritization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Data access level and service criticality

    Why this is correct

    Data access level and service criticality determine potential impact if a vendor is breached, so they drive assessment priority. This satisfies the stem's prioritisation constraint by ranking vendors on inherent risk exposure rather than contract value or relationship length.

  • ✗

    Contract value

    Why it's wrong here

    Contract value reflects financial exposure, not the likelihood or impact of the vendor compromising the organisation, so it cannot drive assessment priority. It is tempting because spend often correlates with dependency, but inherent risk factors such as data sensitivity and system access determine which vendors are assessed first.

  • ✗

    Duration of the relationship

    Why it's wrong here

    Relationship duration says nothing about the data or access the vendor holds, so a long-standing low-risk supplier would be over-prioritised. It is tempting because tenure implies familiarity and trust, yet risk-based prioritisation weights the criticality of the service and the sensitivity of information shared.

  • ✗

    Vendor size

    Why it's wrong here

    Vendor size does not indicate how much sensitive data or privileged access the vendor receives, so a large low-risk supplier could outrank a small critical one. It is tempting because larger vendors appear to carry greater impact, but inherent risk to the organisation is the factor that should dominate prioritisation.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.