Courseiva

CISM Information Security Programme Practice Question

An organization is implementing a third-party risk management (TPRM) program. Which approach best addresses nth-party risk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Requiring that key vendors include security requirements in contracts with their subcontractors

Nth-party risk refers to risks from suppliers of your suppliers. Contractual requirements that cascade down the supply chain are essential to manage this risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Requiring that key vendors include security requirements in contracts with their subcontractors

    Why this is correct

    Nth-party risk arises from subcontractors beyond direct vendors, whom the organisation cannot contract with directly. Requiring key vendors to flow down security requirements into their subcontractor contracts extends governance across that gap, satisfying the constraint of indirect oversight without direct privity.

  • ✗

    Performing on-site audits of all third parties

    Why it's wrong here

    On-site audits examine only the direct third party's controls, revealing nothing about the subcontractors and service providers that party engages. Audits are tempting because they give strong assurance for critical direct vendors, and would be correct when validating a single high-risk supplier's control environment.

  • ✗

    Accepting the risk since it is outside the organization's control

    Why it's wrong here

    Acceptance leaves nth-party exposure unmanaged and unmonitored, so no contractual flow-down, visibility or contingency is established. Acceptance is tempting because the organisation lacks direct control over subcontractors, and would be correct for a low-impact dependency where the residual risk sits within tolerance.

  • ✗

    Conducting annual assessments of all direct vendors only

    Why it's wrong here

    Annual assessments scoped to direct vendors stop at the first tier, leaving the subcontractors those vendors engage unexamined. Periodic direct-vendor review is tempting because it is manageable and repeatable, and would be correct for monitoring first-party supplier compliance where no deeper dependency exists.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.