Third-Party Security Vendor Selection Criteria

Information Security Governance
Answer Correct answer: C — Alignment of vendor's business objectives with enterprise security goals.

An enterprise has decided to procure security services from a third-party vendor to support its information security program. Which of the following is MOST important to include in the vendor selection criteria?

  1. The maturity of the vendor's internal control environment
  2. Feedback from the vendor's previous clients
  3. Alignment of the vendor's business objectives with enterprise security goals Correct Answer
  4. Penetration testing against the vendor's network

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the prioritization of governance over technical assessment; the trap is choosing specific control maturity (A) before ensuring strategic fit (C).

When procuring third-party security services, strategic alignment is the primary selection criterion. Community consensus emphasizes that the vendor's business objectives must align with the enterprise's security goals to ensure program support.

Selecting 'Maturity of the vendor's internal control environment' (A) because it seems like a direct security metric, but strategic alignment is a prerequisite for effective partnership.

Community Discussion (6 comments)

fac161f 👍 2
I answered C, but after looking up maturity models and realizing this was a case of answer written wrongly, I find A is the correct answer. C is written wrong "Alignment of the vendor's business objectives with enterprise security goals" Should be "Alignment of the vendor's security goals with Enterprise Business Objectives" Maturity of internal controls is highly important, look up maturity models. Could be me, but this seems to be the first quesiton that seemed like a trick question if you didnt properly read it. Please correct me if I am wrong.
sausageman 👍 1
C - alignment with corporate governance goal
bronay 👍 1 Selected: C
C alignment with corporate governance goal
shootnot 👍 2
C- helps you select a vendor that matches your business requirements. In the absence of 'C' option 'A' is useless.
yottabyte 👍 1 Selected: C
Alignment of vendors business objectives with enterprise goals.
J3young 👍 2 Selected: C
C. Alignment of the vendor's business objectives with enterprise security goals When selecting a third-party vendor to provide security services, it is crucial to ensure that their business objectives align with the enterprise's security goals. This alignment ensures that the vendor's services and solutions will effectively support the enterprise's information security program.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Alignment of business objectives (C) is the most critical factor because it ensures the vendor's fundamental interests support the enterprise's security posture. If a vendor's business model conflicts with security goals (e.g., data monetization), controls cannot mitigate that risk. This aligns with CISM Domain 1's focus on governance and strategy.

Why the Other Options Are Wrong

Option A (Maturity of internal controls) is important but is a secondary assessment after strategic alignment is confirmed. Option B (Feedback) is a reference check, not a primary criterion. Option D (Penetration testing) is a technical verification tool, not a high-level selection criterion.

Community Comment Notes

Some users (Comment 1) argue that Option A is correct due to the awkward phrasing of Option C, noting that usually security goals align with business objectives, not vice versa. However, the majority (Comments 2-6) and the vote distribution support C, interpreting it as the necessary strategic fit for a successful partnership.

Official Reference

ISACA CISM Review Manual (Domain 1: Information Security Governance)

Exam Strategy

Prioritize 'Governance' and 'Strategy' answers (like alignment) over 'Risk' or 'Technical' answers (like controls or testing) when the question asks for the 'MOST important' factor in a management decision.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide