CISM - Information Security Program - Section 3.10

Manage information security risks associated with external service providers, suppliers and third and fourth parties.

Manage third-party risk and supply chain security by establishing vendor management processes that assess and monitor the security posture of suppliers and service providers. Extend scrutiny to fourth-party risk - the security of the suppliers used by your own suppliers - and include contractual requirements that enforce minimum security standards.

Third-party riskVendor managementSupply chain securityFourth-party risk

Practice question for this objective

Free sampleInformation Security Programhard

A bank relies on a critical software-as-a-service provider that, in turn, runs entirely on a single major cloud platform that several of the bank's other key suppliers also use. The information security manager is briefing the board on what makes this arrangement particularly dangerous beyond the direct provider relationship. Which risk should the manager highlight as the primary governance concern?

  • AVendor lock-in risk, because the contractual switching costs of leaving the software-as-a-service provider have grown high enough to weaken the bank's negotiating position over time.
  • BData residency risk, because the upstream platform may store the bank's processed records in a jurisdiction whose privacy regime differs from the bank's home regulator's rules.
  • CShadow IT risk, because business units may have procured the software-as-a-service provider without routing the engagement through the formal security review and approval process.
  • DFourth-party concentration risk, because many of the bank's critical suppliers depend on the same underlying platform, so one failure there could disrupt several services at once. Correct
Concentration of multiple suppliers on a single shared upstream provider creates fourth-party aggregation risk that direct vendor contracts do not cover. When independent suppliers all sit on one upstream platform, that platform becomes a single point of failure whose disruption cascades simultaneously across every dependent service, an exposure invisible at the level of any one contract.

Why A is wrong: Tempting because lock-in is a genuine sourcing concern, but it speaks to commercial leverage, not the systemic outage exposure created by shared upstream dependence.

Why B is wrong: Tempting because residency is a real compliance issue with cloud chains, but it is a localised legal exposure, not the cross-supplier aggregation risk the scenario centres on.

Why C is wrong: Tempting because unsanctioned procurement is a common failing, but the provider here is already a known critical supplier, so shadow IT does not describe the stated exposure.

Why D is correct: Correct because shared reliance on one upstream platform creates a common point of failure across multiple suppliers, an aggregation exposure the direct contract does not address.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Program objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.