CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An organization is evaluating two vendors for a critical cloud-based ERP system. Which TWO contractual clauses are most important to include to ensure the organization can monitor vendor performance and security? (Select TWO)
⚠ Common exam trap
CISA often tests the distinction between contractual clauses that enable monitoring (audit rights, SLAs) and those that address other concerns (ownership, indemnification, confidentiality), so candidates must focus on the specific objective of monitoring performance and security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit rights
It contractually grants the organization the ability to inspect, assess, and verify the vendor's security controls, processes, and compliance — for example through on-site audits, penetration test reports, or SOC 2 evidence — which is essential for ongoing security monitoring of a critical ERP system. Option D (Service level agreements (SLAs)) is correct because SLAs define measurable performance and availability commitments (e.g., uptime percentages, response and resolution times, penalties for misses), giving the organization the metrics and remedies needed to monitor vendor performance. Option A (Data ownership clause) is not correct here because it establishes who owns the data rather than providing a monitoring mechanism. Option B (Indemnification clause) is not correct because it allocates financial/legal liability after a loss rather than enabling performance or security oversight. Option E (Non-disclosure agreement (NDA)) is not correct because it protects confidentiality of shared information but does not by itself provide performance or security monitoring rights.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data ownership clause
Why it's wrong here
A data ownership clause establishes who holds title to the organisation's data, settling disputes over use and return, yet it imposes no reporting, audit or performance-measurement duty. It fits scenarios where intellectual property ownership is contested, not vendor monitoring.
- ✗
Indemnification clause
Why it's wrong here
Indemnification allocates liability if a third party sues over the vendor's service, so it addresses financial risk rather than ongoing performance or security monitoring. It would be the right clause when protecting against IP infringement claims, not when the requirement is audit rights and service-level reporting.
- ✓
Audit rights
Why this is correct
Audit rights grant the organisation contractual authority to inspect vendor controls, logs and processes, directly satisfying the stem's requirement to monitor vendor security. Without this clause, assurance relies on vendor self-reporting, which is insufficient for a critical cloud ERP system.
- ✓
Service level agreements (SLAs)
Why this is correct
SLAs define measurable performance and availability commitments, giving the organisation contractual grounds to monitor uptime, response times and remediation. This satisfies the stem's monitoring requirement by making vendor performance objectively auditable, with credits or remedies when thresholds are breached.
- ✗
Non-disclosure agreement (NDA)
Why it's wrong here
NDA protects confidential information but does not directly enable monitoring of performance or security.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.