Third-Party Security Vendor Selection Criteria
An enterprise has decided to procure security services from a third-party vendor to support its information security program. Which of the following is MOST important to include in the vendor selection criteria?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the prioritization of governance over technical assessment; the trap is choosing specific control maturity (A) before ensuring strategic fit (C).
When procuring third-party security services, strategic alignment is the primary selection criterion. Community consensus emphasizes that the vendor's business objectives must align with the enterprise's security goals to ensure program support.
Selecting 'Maturity of the vendor's internal control environment' (A) because it seems like a direct security metric, but strategic alignment is a prerequisite for effective partnership.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Alignment of business objectives (C) is the most critical factor because it ensures the vendor's fundamental interests support the enterprise's security posture. If a vendor's business model conflicts with security goals (e.g., data monetization), controls cannot mitigate that risk. This aligns with CISM Domain 1's focus on governance and strategy.Why the Other Options Are Wrong
Option A (Maturity of internal controls) is important but is a secondary assessment after strategic alignment is confirmed. Option B (Feedback) is a reference check, not a primary criterion. Option D (Penetration testing) is a technical verification tool, not a high-level selection criterion.Community Comment Notes
Some users (Comment 1) argue that Option A is correct due to the awkward phrasing of Option C, noting that usually security goals align with business objectives, not vice versa. However, the majority (Comments 2-6) and the vote distribution support C, interpreting it as the necessary strategic fit for a successful partnership.Official Reference
Exam Strategy
Prioritize 'Governance' and 'Strategy' answers (like alignment) over 'Risk' or 'Technical' answers (like controls or testing) when the question asks for the 'MOST important' factor in a management decision.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →