Valid CISM Dumps shared by EduDump.com for Helping Passing CISM Exam! EduDump.com now offer the newest CISM exam dumps, the EduDump.com CISM exam questions have been updated and answers have been corrected get the newest EduDump.com CISM dumps with Test Engine here:
An information security manager is assessing security risk associated with a cloud service provider. Which of the following is the MOST appropriate reference to consult when performing this assessment?
Correct Answer: B
Security control frameworks (e.g., ISO/IEC 27001, NIST SP 800-53, CSA Cloud Controls Matrix) provide a structured and standardized approach to assess the security posture of cloud providers. These frameworks ensure completeness and alignment with best practices. "Standardized security frameworks enable consistent evaluation of third-party providers and alignment with industry-recognized security requirements." - CISM Review Manual 15th Edition, Chapter 3: Third-Party Risk Management* Penetration test results and SLAs are useful, but only frameworks provide comprehensive coverage.