CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An IS auditor is evaluating the vendor selection process for a new system. Which of the following is the most important factor to include in the contract?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit rights
Audit rights are critical for the organization to verify the vendor's controls and compliance, especially for outsourced systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Timeframe for delivery
Why it's wrong here
Delivery timeframe addresses scheduling, not the control objective of protecting the organisation from vendor failure. Contracts must instead specify audit rights, right-to-audit clauses and service levels. Timeframe is tempting because project deadlines matter operationally, but it does not mitigate vendor risk.
- ✗
Fixed price
Why it's wrong here
A fixed price addresses cost certainty, not the auditor's core concern of safeguarding the organisation through contractual control. Audit rights, confidentiality and service-level terms matter instead. Fixed pricing is tempting because budget predictability is valued, yet it leaves vendor performance and compliance unenforceable.
- ✓
Audit rights
Why this is correct
Audit rights contractually permit the buyer to examine the vendor's controls, records and compliance evidence, providing ongoing assurance over the outsourced system. This is the most important factor because it preserves the organisation's ability to verify security and regulatory compliance, satisfying the stem's vendor selection requirement.
- ✗
Warranty period
Why it's wrong here
Warranty period covers defect remediation after delivery, not ongoing vendor accountability for security and service performance. Contracts need audit rights and service-level commitments. Warranty is tempting because it appears to protect the buyer, but it expires and does not govern the vendor relationship.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.