CISM - Information Security Program (33% of the exam) - Section 3.10

Manage information security risks associated with external service providers, suppliers and third and fourth parties.

Manage third-party risk and supply chain security by establishing vendor management processes that assess and monitor the security posture of suppliers and service providers. Extend scrutiny to fourth-party risk - the security of the suppliers used by your own suppliers - and include contractual requirements that enforce minimum security standards.

Third-party riskVendor managementSupply chain securityFourth-party risk

Practice question for this objective

Free sampleInformation Security Programhard

A bank relies on a critical software-as-a-service provider that, in turn, runs entirely on a single major cloud platform that several of the bank's other key suppliers also use. The information security manager is briefing the board on what makes this arrangement particularly dangerous beyond the direct provider relationship. Which risk should the manager highlight as the primary governance concern?

  • AVendor lock-in risk, because the contractual switching costs of leaving the software-as-a-service provider have grown high enough to weaken the bank's negotiating position over time.
  • BData residency risk, because the upstream platform may store the bank's processed records in a jurisdiction whose privacy regime differs from the bank's home regulator's rules.
  • CShadow IT risk, because business units may have procured the software-as-a-service provider without routing the engagement through the formal security review and approval process.
  • DFourth-party concentration risk, because many of the bank's critical suppliers depend on the same underlying platform, so one failure there could disrupt several services at once. Correct
Concentration of multiple suppliers on a single shared upstream provider creates fourth-party aggregation risk that direct vendor contracts do not cover. When independent suppliers all sit on one upstream platform, that platform becomes a single point of failure whose disruption cascades simultaneously across every dependent service, an exposure invisible at the level of any one contract.

Why A is wrong: Tempting because lock-in is a genuine sourcing concern, but it speaks to commercial leverage, not the systemic outage exposure created by shared upstream dependence.

Why B is wrong: Tempting because residency is a real compliance issue with cloud chains, but it is a localised legal exposure, not the cross-supplier aggregation risk the scenario centres on.

Why C is wrong: Tempting because unsanctioned procurement is a common failing, but the provider here is already a known critical supplier, so shadow IT does not describe the stated exposure.

Why D is correct: Correct because shared reliance on one upstream platform creates a common point of failure across multiple suppliers, an aggregation exposure the direct contract does not address.

See more CISM practice questions, answers explained.

Exam traps in Information Security Program

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • Subscribing to additional commercial threat intelligence feeds, so that the security team is alerted as early as possible whenever a new component vulnerability is disclosed publicly.

    Why it is wrong: Tempting because earlier warning sounds valuable, but knowing a flaw exists does not tell the organisation which of its products embed the affected component.

  • Running a one-off technical penetration test of the provider's public interface before go-live to prove that the service is secure enough to be integrated at all.

    Why it is wrong: Tempting as concrete assurance, but a single pre-launch test is a point-in-time snapshot that says nothing about how the provider's controls hold up across the ongoing relationship.

  • A fixed annual price-protection clause that caps any increase in the provider's processing fees, so the cost of the outsourced service stays predictable across the term.

    Why it is wrong: Tempting because budget certainty matters to management, but a pricing clause governs commercials and does nothing to protect data security through the chain.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.