certslothcertsloth
CISA/Topic 04

ISACA / Professional

Security Programs, Suppliers and Useful Metrics

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Fund the capability, assign an owner, test the result.

Must remember

Build a roadmap from current-state gaps to target outcomes, with dependencies, staffing, budget and milestones. Integrate security into procurement, development, HR and operations instead of relying on a separate review at the end. Asset inventory and classification identify what needs protection and who can decide its handling.

Select preventive, detective and corrective controls with operational feasibility in mind. Test design effectiveness and operating effectiveness separately: a well-written access-review procedure may never be followed. Retain evidence, address exceptions and verify remediation. Compensating controls require demonstrable coverage of the original risk, not just convenient substitution.

Awareness programs address broad behavior; role-specific training prepares people such as developers, administrators and responders. Measure demonstrated behavior and exposure reduction alongside completion. A high training-attendance rate can coexist with unsafe credential handling.

Supplier due diligence examines criticality, data access, security practices, continuity, subcontractors and exit options. Contracts define responsibilities, incident notification, audit rights, service levels and secure data return/deletion. Review assurance-report scope, period and exceptions, including customer responsibilities. Ongoing monitoring is necessary because a supplier’s condition can change after onboarding.

KPIs track performance, KRIs signal changing exposure, and control indicators show whether safeguards operate. Choose measures with thresholds, owners, trend context and a decision they support. Report unresolved exceptions and accepted risks honestly. A lower incident count could reflect weaker detection rather than improved security.

Choose under exam pressure

Requirement Choice and reason
Check a supplier assurance report Read scope, period, exceptions and complementary customer controls.
Demonstrate training effectiveness Observe relevant behavior and risk outcomes.
Program slips due to skill gaps Adjust staffing, sequencing or scope with accountable sponsors.

Traps

  • Certification badges do not eliminate supplier risk.
  • A metric without an action threshold may become decorative reporting.

Active recall

1. Design versus operating effectiveness?

Whether a control could address the risk versus whether it actually works consistently.

2. Why assess fourth parties?

Subcontractors can introduce dependencies and access outside the immediate contract.

3. What is a KRI?

An indicator of changing risk exposure.

4. Why review customer controls in an assurance report?

The provider’s assurance may assume the customer performs specific controls.

5. Why test remediation?

A closed ticket does not prove the weakness was fixed.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.