CISM Information Security Programme Practice Question
A company is implementing a third-party risk management program and needs to prioritize vendors for assessment. Which factor should be given the highest weight?
⚠ Common exam trap
CISM often tests the misconception that financial or relationship factors (contract value, duration, vendor size) are primary risk indicators, when in fact data access and service criticality are the core determinants of third-party risk exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data access level and service criticality
The highest-weighted factor in third-party risk prioritization is the combination of data access level and service criticality. This is because risk exposure is directly proportional to the sensitivity of data the vendor can access and how essential the vendor's service is to business operations. A vendor with access to regulated data (e.g., PII, PHI) or that supports a critical business function poses a significantly higher risk if compromised, regardless of contract value or vendor size. Thus, these two dimensions determine the potential impact of a vendor-related incident, making them the primary drivers for assessment prioritization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data access level and service criticality
Why this is correct
Data access level and service criticality determine potential impact if a vendor is breached, so they drive assessment priority. This satisfies the stem's prioritisation constraint by ranking vendors on inherent risk exposure rather than contract value or relationship length.
- ✗
Contract value
Why it's wrong here
Contract value reflects financial exposure, not the likelihood or impact of the vendor compromising the organisation, so it cannot drive assessment priority. It is tempting because spend often correlates with dependency, but inherent risk factors such as data sensitivity and system access determine which vendors are assessed first.
- ✗
Duration of the relationship
Why it's wrong here
Relationship duration says nothing about the data or access the vendor holds, so a long-standing low-risk supplier would be over-prioritised. It is tempting because tenure implies familiarity and trust, yet risk-based prioritisation weights the criticality of the service and the sensitivity of information shared.
- ✗
Vendor size
Why it's wrong here
Vendor size does not indicate how much sensitive data or privileged access the vendor receives, so a large low-risk supplier could outrank a small critical one. It is tempting because larger vendors appear to carry greater impact, but inherent risk to the organisation is the factor that should dominate prioritisation.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.