CISM Information Security Programme Practice Question
During a third-party risk assessment, the security team discovers that a critical vendor's sub-supplier (nth party) has access to sensitive data. The vendor contract does not address nth-party risk. What is the BEST course of action?
⚠ Common exam trap
CISM often tests the distinction between risk acceptance, risk transfer, and risk mitigation; candidates may incorrectly choose to accept the risk because the vendor is contractually responsible, but the contract's silence on nth-party risk means the risk is not effectively transferred.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Revise the contract to require the vendor to flow down security requirements to sub-suppliers
The core issue is that the vendor contract does not address nth-party (sub-supplier) risk, so the organization has no contractual leverage to require the vendor to manage its sub-suppliers. The best course of action is to revise the contract to include flow-down clauses that require the vendor to impose security requirements on its sub-suppliers, thereby extending the organization's security posture through the supply chain. This addresses the root cause—lack of contractual control—and is a preventive, governance-level action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk because the vendor is contractually responsible
Why it's wrong here
Contractual responsibility does not transfer the actual data-protection obligation, and the contract is silent on nth-party risk, so no enforceable control exists. Acceptance is tempting because vendor accountability feels sufficient, but it is valid only when residual risk falls within the organisation's documented risk appetite and has formal sign-off.
- ✓
Revise the contract to require the vendor to flow down security requirements to sub-suppliers
Why this is correct
Contractual flow-down clauses extend security requirements to sub-suppliers, closing the nth-party gap the existing agreement leaves open. This addresses the root cause — absent contractual control — rather than merely monitoring a vendor that has no obligation to enforce sub-supplier security.
- ✗
Perform an on-site assessment of the sub-supplier
Why it's wrong here
An on-site assessment of the sub-supplier is disproportionate and does not remedy the contractual gap; the vendor must be made accountable for nth parties. It tempts as thorough due diligence, but the missing contract clause is the actual control failure to address.
- ✗
Request that the vendor terminate the sub-supplier relationship
Why it's wrong here
Terminating the sub-supplier relationship is a commercial remedy the security team cannot impose, and it ignores the live data exposure. Contractual remedies belong to procurement and legal, not risk assessment. The tempting appeal is decisive risk elimination, which would be valid only if the nth party were non-critical and no data had already been shared.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.