CISM Information Security Programme Practice Question
A company uses a SaaS provider that processes sensitive customer data. The provider undergoes annual SOC 2 audits. Which additional step is essential to manage nth-party risk?
⚠ Common exam trap
CISM often tests the misconception that a SOC 2 report or right-to-audit clause is sufficient for nth-party risk, when the real gap is subcontractor visibility and control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require the provider to disclose and assess the security of its subcontractors
Requiring the provider to disclose and assess the security of its subcontractors is essential because SOC 2 audits typically cover only the provider's own controls, not those of its downstream vendors. This step extends risk visibility to the nth party, ensuring that subcontractors meet equivalent security standards and that the provider manages them contractually. It addresses the gap left by annual SOC 2 reviews and right-to-audit clauses, which focus on the primary provider.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require the provider to disclose and assess the security of its subcontractors
Why this is correct
SOC 2 reports cover only the provider's own controls, leaving subcontractor security unverified. Requiring disclosure and assessment of subcontractors extends assurance to the nth parties actually touching customer data, closing the transitive risk gap that direct audits cannot address.
- ✗
Include a right-to-audit clause for the provider
Why it's wrong here
A right-to-audit clause grants the company contractual permission to audit the provider itself, not the provider's subservice organisations, so it does not address nth-party risk. It tempts because right-to-audit clauses are standard vendor-contract controls, and they are correct for direct-provider oversight, but nth-party risk requires visibility into subcontractors.
- ✗
Conduct penetration testing on the provider's application
Why it's wrong here
Penetration testing the provider's application assesses the provider's own security posture, not its subservice organisations, and typically breaches the SaaS contract without authorisation. It tempts because penetration testing is a valid assurance technique for first-party systems, but nth-party risk concerns the provider's subcontractors, which testing the provider's application does not reach.
- ✗
Review the SOC 2 report annually
Why it's wrong here
Reviewing the SOC 2 report annually merely repeats the provider's own attestation, which the company already receives; it does not assess the provider's own subservice organisations. It tempts because SOC 2 reports are the standard assurance artefact, and reviewing them is correct for direct-provider due diligence, but nth-party risk requires scrutiny one layer deeper.
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.