hardMultiple Choice
CISM Practice Question: A global financial services firm with 15,000…
A global financial services firm with 15,000 employees has recently experienced a significant data breach due to inadequate oversight of third-party vendors. The breach originated from a cloud service provider that had been granted elevated access without a formal risk assessment or contract review. The board has directed the CISO to overhaul the information security governance framework to prevent recurrence. Currently, the organization has a decentralized security model where each business unit manages its own vendor relationships. The CISO proposes a centralized governance body. Which of the following is the BEST course of action to establish effective governance over third-party risk?
⚠ Common exam trap
CISM often tests the difference between tactical controls (penetration tests, training) and strategic governance (centralized TPRM program), and candidates frequently choose a control that addresses a symptom rather than the root cause.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establish a central third-party risk management program with a defined policy and vendor assessment process
Establishing a central third-party risk management program with a defined policy and vendor assessment process is the best course of action because it directly addresses the root cause: decentralized, inconsistent oversight of third-party vendors. A centralized program ensures uniform risk assessment, contract review, and ongoing monitoring, which prevents the gaps that led to the breach. This approach aligns with CISM's emphasis on governance, risk management, and compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Establish a central third-party risk management program with a defined policy and vendor assessment process
Why this is correct
A central third-party risk management programme with defined policy and vendor assessment directly addresses the decentralised oversight that allowed elevated access without risk assessment or contract review, giving the governance body consistent control across all business units.
- ✗
Conduct quarterly penetration tests on all third-party systems
Why it's wrong here
Penetration tests probe deployed systems for exploitable flaws; they neither assess vendor risk before granting elevated access nor enforce contractual controls, so the breach's root cause persists. Testing suits validating existing third-party defences, not governing onboarding decisions, where due diligence and contract review are required.
- ✗
Provide annual security awareness training for employees managing vendors
Why it's wrong here
Training raises awareness among vendor managers but leaves the decentralised model intact, so no consistent risk assessment or approval gate exists. It is tempting as a low-cost cultural control, yet the stem demands a centralised governance body with authority over third-party access decisions.
- ✗
Mandate that all vendor contracts include data protection clauses
Why it's wrong here
Contract clauses address legal terms for individual engagements but do not create the centralised oversight, risk assessment and ongoing vendor monitoring the breach exposed. It is tempting because contracts are a familiar control, yet the stem requires governance over who grants elevated third-party access and how that risk is assessed.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.