mediumMultiple Choice
CISA Outsourcing software development Practice Question
A company is outsourcing software development. What is the IS auditor's PRIMARY concern?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Protection of intellectual property and data
Protection of intellectual property and data is the primary concern for an IS auditor when outsourcing software development because it represents the highest risk to the organization. While vendor methodology, financial stability, and SLA compliance are important, they are secondary to ensuring that sensitive data and proprietary information are safeguarded against unauthorized access or disclosure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The vendor's development methodology
Why it's wrong here
Methodology affects process quality but not the fundamental loss of control over code, data, and intellectual property inherent in outsourcing development. The auditor's primary concern is that exposure. Reviewing methodology is correct when assessing a vendor's engineering capability during selection, not the overarching outsourcing risk.
- ✓
Protection of intellectual property and data
Why this is correct
Outsourcing transfers code and data to a third party, so the auditor's primary concern is safeguarding intellectual property and confidential data through contractual controls, access restrictions and monitoring, since loss or misuse directly threatens the organisation's assets and compliance obligations.
- ✗
The vendor's financial stability
Why it's wrong here
Financial stability affects vendor viability, not the primary outsourcing risk: loss of control over code quality, intellectual property and change management. Auditors prioritise these because the company retains accountability. Vendor solvency is the correct focus when assessing long-term supplier continuity for a critical, single-sourced service.
- ✗
Compliance with service level agreements
Why it's wrong here
SLA compliance addresses delivery performance, not the auditor's primary concern when source code and intellectual property leave the organisation. Outsourcing transfers control of code, data, and development practices to the vendor. SLA monitoring is the right focus for operational service delivery, such as uptime or response times.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.