hardMultiple Choice
CISA Practice Question: An IS auditor is evaluating a system development…
An IS auditor is evaluating a system development project that uses an outsourced team. The contract allows the vendor to reuse some of the developed code in other projects. What is the auditor's PRIMARY concern?
⚠ Common exam trap
The trap here is that candidates focus on operational risks (delays, maintenance, quality) rather than the contractual and legal risk of losing intellectual property rights, which is the auditor's primary concern when the vendor is explicitly allowed to reuse code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The organization may lose control of intellectual property.
The contract clause allowing the vendor to reuse developed code in other projects directly transfers ownership or licensing rights of the intellectual property (IP) to the vendor. This means the organization may lose exclusive control over the code, potentially allowing competitors to access proprietary logic or algorithms. The IS auditor's primary concern is safeguarding the organization's IP assets, as this loss can have long-term strategic and competitive implications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The vendor might not deliver on time.
Why it's wrong here
Schedule slippage is a delivery risk unrelated to the code-reuse clause; it would concern the auditor regardless of reuse rights. The clause's actual exposure is intellectual property and confidentiality — reusable code may embed the organisation's logic or data into other clients' systems.
- ✓
The organization may lose control of intellectual property.
Why this is correct
Contractual reuse rights let the vendor redeploy code built for this organisation into other clients' projects, eroding exclusive ownership and potentially exposing proprietary logic or data-handling design. The primary concern is therefore loss of control over intellectual property, not delivery timelines or code quality.
- ✗
The vendor may not maintain the code after the project ends.
Why it's wrong here
Ongoing maintenance is a support and warranty concern, not something the reuse clause creates. The clause's real exposure is intellectual property and confidentiality: code containing the organisation's proprietary logic or data may be reused for other clients, leaking competitive or sensitive information.
- ✗
The vendor may use substandard development practices.
Why it's wrong here
Substandard development practices are a general outsourcing quality risk, present with or without code reuse. The reuse clause specifically raises intellectual property and confidentiality exposure, because the vendor may embed the organisation's proprietary logic or data in code delivered to other clients.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.