Courseiva
mediumMultiple Choice

CISA Outsourcing software development Practice Question

A company is outsourcing software development. What is the IS auditor's PRIMARY concern?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Protection of intellectual property and data

Protection of intellectual property and data is the primary concern for an IS auditor when outsourcing software development because it represents the highest risk to the organization. While vendor methodology, financial stability, and SLA compliance are important, they are secondary to ensuring that sensitive data and proprietary information are safeguarded against unauthorized access or disclosure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The vendor's development methodology

    Why it's wrong here

    Methodology affects process quality but not the fundamental loss of control over code, data, and intellectual property inherent in outsourcing development. The auditor's primary concern is that exposure. Reviewing methodology is correct when assessing a vendor's engineering capability during selection, not the overarching outsourcing risk.

  • ✓

    Protection of intellectual property and data

    Why this is correct

    Outsourcing transfers code and data to a third party, so the auditor's primary concern is safeguarding intellectual property and confidential data through contractual controls, access restrictions and monitoring, since loss or misuse directly threatens the organisation's assets and compliance obligations.

  • ✗

    The vendor's financial stability

    Why it's wrong here

    Financial stability affects vendor viability, not the primary outsourcing risk: loss of control over code quality, intellectual property and change management. Auditors prioritise these because the company retains accountability. Vendor solvency is the correct focus when assessing long-term supplier continuity for a critical, single-sourced service.

  • ✗

    Compliance with service level agreements

    Why it's wrong here

    SLA compliance addresses delivery performance, not the auditor's primary concern when source code and intellectual property leave the organisation. Outsourcing transfers control of code, data, and development practices to the vendor. SLA monitoring is the right focus for operational service delivery, such as uptime or response times.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.