CISA - Governance and Management of IT - Section 2.2

Evaluate IT resource management and IT vendor management practices.

Describe how IT resource management ensures that people, hardware and software assets are acquired, deployed and retired in a controlled manner. Evaluate IT vendor management and outsourcing arrangements to confirm that third-party risks are identified and contractually mitigated.

IT resource managementIT vendor managementthird-party managementoutsourcing

Practice question for this objective

Free sampleGovernance and Management of ITmedium

Which statement BEST distinguishes IT vendor management from third-party risk management as the IS auditor would evaluate them?

  • AVendor management is concerned with cyber risk only, whereas third-party risk management covers the wider commercial relationship with each strategic supplier of the organisation.
  • BVendor management is a board-level oversight activity, while third-party risk management is delegated to procurement to negotiate price reductions and renewal terms with suppliers.
  • CVendor management focuses on commercial performance against service-level targets, while third-party risk management focuses on the residual risk the relationship introduces across the enterprise. Correct
  • DVendor management addresses only outsourced data centres, while third-party risk management addresses software-as-a-service and other cloud arrangements that bypass classical procurement.
Distinguish IT vendor management from third-party risk management by their respective focus on commercial performance and on residual enterprise risk. Vendor management is a performance and contractual discipline that tracks service levels, deliverables and commercial value, while third-party risk management is an enterprise risk discipline that evaluates how each supplier relationship affects information security, resilience, regulatory and concentration risk. ISACA guidance and ISO/IEC 27036 treat them as complementary but distinct, which is why an IS auditor expects separate but linked governance artefacts.

Why A is wrong: This inverts the disciplines, since vendor management is the broader commercial discipline and third-party risk management is the risk-focused overlay; an auditor would mark this confusion as incorrect.

Why B is wrong: This is tempting because procurement does sit close to vendors, but governance of third-party risk sits with senior management and the board, not the procurement desk; this misallocates accountability.

Why C is correct: This captures the recognised split: vendor management is performance and contract-led, while third-party risk management is risk-led and covers information security, resilience, compliance and concentration exposure across the supplier portfolio.

Why D is wrong: This narrow framing is plausible to a candidate thinking only of hosting, but both disciplines apply across the whole supplier portfolio regardless of delivery model, so the scope claim is wrong.

See more CISA practice questions, answers explained.

More in this domain

Back to all Governance and Management of IT objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.