Courseiva

CISM Information Security Programme Practice Question

In a third-party risk management programme, what is the primary purpose of vendor tiering?

⚠ Common exam trap

CISM often tests the misconception that vendor tiering is about equalizing oversight or administrative convenience, when the correct answer always ties back to risk-based prioritization of security assessments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To prioritize which vendors require more rigorous security assessments

Vendor tiering is a risk-based classification process that segments third parties according to the criticality of the data they handle, the level of access they have to systems, and the potential business impact of a breach or failure. The primary purpose is to allocate limited security assessment resources efficiently by focusing the most rigorous due diligence, contractual controls, and ongoing monitoring on the highest-risk vendors. This ensures that oversight is proportionate to risk rather than uniform, which is a core CISM principle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To assign responsibility for vendor management to different teams

    Why it's wrong here

    Tiering classifies vendors by risk and criticality to set due diligence depth and review frequency; it does not allocate ownership across teams. Assigning responsibility is a governance decision made separately, which is why this option appeals when designing RACI structures. Tiering would be correct where the goal is proportionate oversight of vendors.

  • ✓

    To prioritize which vendors require more rigorous security assessments

    Why this is correct

    Tiering classifies vendors by risk and criticality, so assessment effort and due diligence depth are proportionate. This directly satisfies the programme's constraint of focusing rigorous security assessments on the vendors that pose the greatest risk to the organisation.

  • ✗

    To ensure all vendors receive the same level of oversight

    Why it's wrong here

    Tiering deliberately applies differentiated oversight: critical vendors get deeper due diligence and monitoring, while low-risk vendors receive lighter review. Uniform oversight for every vendor is the opposite of tiering's purpose, and would be correct only where all vendors carried identical risk exposure.

  • ✗

    To determine the vendor's pricing structure

    Why it's wrong here

    Tiering classifies vendors by risk and criticality to set due diligence depth, contract terms and monitoring frequency; pricing structure plays no part in the classification. Pricing analysis would be correct for procurement or cost-optimisation work, not for determining third-party risk oversight.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.