CISM Information Security Programme Practice Question
A multinational organization is implementing a vendor risk management programme. Which THREE of the following should be included in the programme to effectively manage nth-party risk? (Select THREE.)
⚠ Common exam trap
CISM often tests the misconception that assessing all subcontractors annually or requiring insurance is sufficient, when the focus should be on contractual flow-down, audit rights, and disclosure — the three pillars of nth-party risk management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Include contractual clauses that require vendors to pass down security requirements to subcontractors
Option A is correct because nth-party risk arises from subcontractors, so contracts must include flow-down clauses that propagate the organization's security, privacy, and compliance requirements to those downstream parties. Option B is correct because including audit rights over subcontractors in vendor agreements gives the organization the contractual ability to verify nth-party controls directly or through the vendor, which is essential for oversight. Option D is correct because visibility into which subcontractors exist and their security posture is a prerequisite for assessing and managing nth-party risk; without disclosure, the organization cannot evaluate downstream exposure. Option C is not marked correct because conducting annual security assessments of all subcontractors is not a universally required or practical programme element; assessments should be risk-based and proportionate, not blanket annual reviews of every subcontractor. Option E is not marked correct because requiring vendors to obtain insurance for subcontractors addresses financial risk transfer only and does not by itself manage nth-party security risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Include contractual clauses that require vendors to pass down security requirements to subcontractors
Why this is correct
Contractual flow-down clauses extend security obligations to subcontractors, directly addressing nth-party risk where fourth parties operate beyond the organization's direct visibility. This satisfies the stem's requirement to manage risk through the vendor chain, since primary vendor agreements alone cannot bind subcontractors without explicit pass-down provisions.
- ✓
Include the right to audit subcontractors in vendor contracts
Why this is correct
An audit right over subcontractors gives the organisation enforceable visibility and verification beyond the primary vendor, which is the core gap in nth-party risk. It satisfies the need to independently validate subcontractor controls rather than relying on vendor assurances.
- ✗
Conduct annual security assessments of all subcontractors
Why it's wrong here
Annual assessments of all subcontractors are point-in-time and unscalable across a multinational nth-party chain, missing continuous monitoring and flow-down requirements. It tempts because periodic security assessments are valid for direct, stable vendors where annual assurance matches the risk profile.
- ✓
Require vendors to disclose all subcontractors and their security posture
Why this is correct
Mandatory disclosure of subcontractors and their security posture provides the inventory and risk data needed to identify nth parties at all. Without this visibility, the organisation cannot assess or manage risks it does not know exist.
- ✗
Require vendors to obtain insurance for subcontractors
Why it's wrong here
Insurance transfers financial loss to the vendor; it does not give the organization visibility or control over subcontractors' security, so nth-party risk remains unmanaged. It tempts because insurance is a legitimate risk-transfer control for direct vendor liability, where financial compensation is the objective.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.