Valid CRISC Dumps shared by ExamDiscuss.com for Helping Passing CRISC Exam! ExamDiscuss.com now offer the newest CRISC exam dumps, the ExamDiscuss.com CRISC exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com CRISC dumps with Test Engine here:
Which of the following is the PRIMARY reason to perform periodic vendor risk assessments?
Correct Answer: B
The primary reason to perform periodic vendor risk assessments is to monitor the vendor's control effectiveness. A vendor risk assessment is a process of evaluating the risks associated with outsourcing a service or function to a third-party vendor. The assessment should be performed periodically to ensure that the vendor is complying with the contractual obligations, service level agreements, and security standards, and that the vendor's controls are operating effectively to mitigate the risks. Providing input to the organization's risk appetite, verifying the vendor's ongoing financial viability, and assessing the vendor's risk mitigation plans are other possible reasons, but they are not as important as monitoring the vendor's control effectiveness. References = ISACA Certified in Risk and Information Systems Control (CRISC) Certification Exam Question and Answers, question 11; CRISC Review Manual, 6th Edition, page 144.