Information Systems Acquisition, Development, and Implementation →hardMultiple ChoiceObjective-mapped
CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An organization is deciding between developing a custom application and purchasing a commercial off-the-shelf (COTS) product. The project manager favors a COTS solution because it offers faster deployment. Which of the following is the MOST important consideration for the IS auditor to evaluate in this build vs. buy decision?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The degree of vendor dependency and ability to customize
Vendor dependency is a critical risk in COTS acquisitions. The organization may become reliant on the vendor for updates, support, and customizations, which can affect long-term flexibility and costs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Availability of skilled developers to maintain the custom solution
Why it's wrong here
This is relevant for custom development but not the most important when evaluating COTS.
- ✗
User training requirements for the new system
Why it's wrong here
Training is manageable and not a primary decision factor compared to long-term vendor dependence.
- ✗
Total cost of ownership including maintenance and licensing
Why it's wrong here
While important, cost is not the most critical risk compared to vendor dependency, which can have broader strategic implications.
- ✓
The degree of vendor dependency and ability to customize
Why this is correct
Vendor lock-in can limit future options and increase costs if the vendor changes terms or goes out of business.
Go deeper
Related to this question
About these practice questions
One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.