CISM Information Security Programme Practice Question
Which THREE of the following are key activities in a third-party risk management (TPRM) program?
⚠ Common exam trap
CISM often tests whether candidates confuse vendor management with granting access or performing HR-style checks, when the core activities are assessment, contractual controls, and ongoing monitoring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ongoing monitoring of vendor security posture
Option A (Ongoing monitoring of vendor security posture) is correct because TPRM requires continuous oversight of a vendor's security controls, compliance status, and threat exposure after onboarding, using methods such as periodic reassessments, security ratings services, and audit reviews. Option C (Negotiating contract security requirements) is correct because TPRM includes embedding security, privacy, data-handling, breach-notification, and right-to-audit clauses into vendor contracts to establish enforceable obligations and risk allocation. Option D (Onboarding risk assessment for new vendors) is correct because TPRM begins with due diligence before engagement, evaluating the vendor's security posture, data access, criticality, and compliance against organizational risk tolerance. Option B (Providing vendor with access to internal network) is not a TPRM activity; it is an operational access decision that should be minimized and controlled, not a core program function. Option E (Performing background checks on vendor employees) is not a TPRM program activity; personnel screening is typically the vendor's responsibility under contract, and TPRM focuses on organizational vendor risk rather than individual employee vetting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ongoing monitoring of vendor security posture
Why this is correct
Ongoing monitoring tracks vendor security posture after onboarding, catching new breaches, expired certifications or degraded controls that initial due diligence missed. This satisfies TPRM's requirement for continuous oversight across the vendor relationship lifecycle, not just at selection.
- ✗
Providing vendor with access to internal network
Why it's wrong here
Granting network access is an operational onboarding action performed after risk assessment and contractual controls are agreed, not a TPRM activity itself. It is tempting because third parties frequently need connectivity to deliver services, which would make it relevant to access provisioning rather than to risk management.
- ✓
Negotiating contract security requirements
Why this is correct
Negotiating contract security requirements embeds breach notification, audit rights, data handling and liability terms into the vendor agreement. This gives the organisation enforceable remedies and visibility, satisfying TPRM's need to translate assessed risk into binding obligations before the relationship begins.
- ✓
Onboarding risk assessment for new vendors
Why this is correct
Onboarding risk assessment evaluates a new vendor's security controls, data access and criticality before any contract or data sharing occurs. This satisfies TPRM's requirement to identify inherent risk at the earliest point, enabling proportionate due diligence and appropriate contractual safeguards.
- ✗
Performing background checks on vendor employees
Why it's wrong here
Background checks on vendor staff are the vendor's own employment responsibility, discharged through contractual clauses and assurance reporting, not an activity the customer performs. It is tempting because screening reduces insider risk, and would be correct if the question concerned due diligence over the vendor's security programme.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.