Courseiva
mediumMultiple Choice

CISM Practice Question: After a security incident, the board holds the…

After a security incident, the board holds the CISO accountable. The CISO argues that the incident was caused by a failure in the third-party risk management process. Which of the following governance deficiencies is most likely the root cause?

⚠ Common exam trap

ISACA often tests the distinction between governance (board-level policy) and management (operational implementation), so candidates mistakenly pick a visible operational failure (like a missing contract clause or technical control) instead of recognizing that the root cause is the absence of a board-approved policy that would have mandated those controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

There was no board-approved policy for assessing and monitoring third-party risk.

The board holds the CISO accountable because governance ultimately flows from the board's approval of policies. Without a board-approved third-party risk management policy, there is no authoritative mandate to enforce security requirements, conduct assessments, or monitor vendors. This governance gap means the organization lacks the foundational directive that drives all downstream processes, making it the most likely root cause of the incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    There was no board-approved policy for assessing and monitoring third-party risk.

    Why this is correct

    Without a board-approved third-party risk policy, no mandate existed for assessing or monitoring vendors, so oversight of suppliers was undefined. The governance deficiency is the absent policy establishing accountability and requirements, not merely weak operational execution.

  • ✗

    The third-party contract did not specify security requirements.

    Why it's wrong here

    A contract omitting security requirements is a documentation gap; the governance deficiency is the absence of due diligence and risk assessment before engaging the vendor, which the contract merely reflects. It is tempting because contracts are tangible artefacts, but it would be correct where the procurement process itself was sound and only the written terms were deficient.

  • ✗

    The organization did not implement technical controls to monitor third-party access.

    Why it's wrong here

    Missing technical monitoring controls is an operational control gap, not the governance failure that let the third party be engaged without oversight; monitoring would not have prevented the underlying risk acceptance. It is tempting because monitoring is a recognised control, but it would be correct where continuous oversight of live third-party activity is the stated requirement.

  • ✗

    The incident response plan did not cover third-party related incidents.

    Why it's wrong here

    An incident response plan scoped only to internal systems is a response-planning gap; it does not explain why the third-party risk was accepted or overlooked during onboarding. It is tempting because response coverage is a governance concern, but it would be correct where the failure occurred during incident handling rather than during vendor risk assessment.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.