Courseiva

CISM Information Security Risk Management Practice Question

A healthcare insurer's third-party risk manager learns that a critical claims-processing vendor has been acquired by a foreign parent company subject to different data protection laws. The vendor contract contains no change-of-control clause. What should the risk manager do FIRST?

⚠ Common exam trap

The trap here is assuming that an unchanged service-level agreement means unchanged risk, when ownership changes can alter legal jurisdiction and data protection obligations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform a risk assessment of the change in ownership and its impact on data protection obligations.

A change of control at a critical vendor is a risk event that must be reassessed before any treatment decision. Because the contract lacks a change-of-control clause, the organization cannot rely on contractual levers and must understand the new legal, privacy, and operational exposure. Assessing first supports an informed choice among renegotiation, added controls, or managed exit, and preserves evidence of due diligence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately terminate the vendor contract and migrate claims processing in-house.

    Why it's wrong here

    Terminating a critical claims-processing vendor without a transition plan would create severe operational and regulatory disruption, and the contract contains no change-of-control clause that would even permit immediate termination. This reaction is disproportionate and ignores the need for assessment first. Risk management requires understanding the exposure before selecting a treatment, so immediate termination is not the appropriate first step.

  • ✓

    Perform a risk assessment of the change in ownership and its impact on data protection obligations.

    Why this is correct

    A change in vendor ownership can alter legal jurisdiction, data handling practices, and breach notification obligations, so the risk manager must first assess the resulting risk to the organization. This assessment informs whether to renegotiate, add controls, or exit the relationship. Treating the acquisition as a trigger for reassessment aligns with continuous third-party risk management and gives decision-makers the facts they need.

  • ✗

    Report the acquisition to the regulator and await instructions before taking any action.

    Why it's wrong here

    Regulatory notification may eventually be required, but it is not the first action and regulators generally expect the organization to manage its own third-party risk. Deferring all action to the regulator leaves the organization passive and delays essential internal assessment. The risk manager should first understand the exposure, then determine whether and when notification is required under applicable rules.

  • ✗

    Accept the change because the vendor's service-level agreement remains unchanged.

    Why it's wrong here

    An unchanged SLA addresses availability and performance, not the legal and privacy exposure created by foreign ownership. Data protection obligations, cross-border transfer restrictions, and breach notification duties can change even when service levels do not. Accepting the change without assessment ignores the new regulatory and reputational risk and may violate the insurer's own compliance obligations.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.