Certified Information Security Manager (CISM)Information Security GovernanceHard

An organization relies heavily on its supply chain for critical components. A recent audit highlighted significant information security risks originating from third-party vendors. To address this, the CISO proposes establishing a formal vendor risk management (VRM) program. Which of the following is the MOST important element to include in the VRM program's initial design?

  1. AMandatory annual security awareness training for all third-party vendor employees.
  2. BClear contractual clauses outlining security requirements and right-to-audit for all vendors.
  3. CDefined metrics and reporting for ongoing monitoring of vendor security posture.
  4. DA standardized security questionnaire to be completed by all third-party vendors.
Show answer & explanation

Correct answer: B. Clear contractual clauses outlining security requirements and right-to-audit for all vendors.

Clear contractual clauses outlining security requirements and the right-to-audit are the most important initial element. These clauses establish the legal basis for all subsequent VRM activities, ensuring the organization has the authority to enforce security standards and verify compliance.

Why the other options are wrong

  • A. While beneficial, mandatory training for vendor employees is difficult to enforce and verify without a contractual basis.
  • C. Metrics and reporting are for ongoing monitoring, which comes after establishing the foundational requirements and legal enforceability.
  • D. A questionnaire is a tool for assessment, but without contractual backing, the vendor is not obligated to comply or meet the standards.

Vendor Risk Management (VRM) Foundations

The essential initial components and legal mechanisms required to establish an effective program for managing information security risks posed by third-party vendors.

  • Contractual agreements are paramount.
  • Establishes legal enforceability of security requirements.
  • Provides the basis for audits and monitoring.

Memory trick: Start with the handshake and the fine print; everything else flows from there.

More Information Security Governance questions