CISA Practice Question: Information Systems Operations and Business Resilience
An organization is negotiating a contract with a cloud service provider. Which clause is most important for the IS auditor to ensure is included?
⚠ Common exam trap
CISA often tests the misconception that an SLA with penalties or data localization clauses provide equivalent assurance to a right-to-audit — candidates must recognize that only the right-to-audit gives the auditor legal standing to obtain control evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Right-to-audit clause.
The right-to-audit clause is the most critical contractual provision for an IS auditor because it grants the organization the legal right to inspect the cloud provider's controls, processes, and records — either directly or via third-party attestations (SOC 2, ISO 27001). Without it, the auditor cannot obtain sufficient evidence to opine on the effectiveness of controls over outsourced data and processing. It is the contractual foundation that makes all other assurance activities possible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data localization requirements.
Why it's wrong here
Data localisation constrains where data is stored, but it does not by itself guarantee the security, privacy or audit rights the auditor must secure in the contract. It is tempting because residency is a common regulatory demand, and it would be correct when legislation mandates in-country storage.
- ✓
Right-to-audit clause.
Why this is correct
A right-to-audit clause contractually guarantees the IS auditor independent access to the provider's controls, records and evidence. Without it, the organisation cannot verify that the outsourced service meets its security and compliance obligations, leaving assurance dependent solely on the provider's own reporting.
- ✗
Automatic renewal terms.
Why it's wrong here
Automatic renewal terms govern contract duration and termination notice, giving no assurance over data protection, access control or breach notification. It is tempting because renewal affects cost and lock-in, and it would be correct when the audit objective is avoiding unintended contract extension rather than safeguarding data.
- ✗
Service level agreement (SLA) with penalties.
Why it's wrong here
An SLA with penalties addresses availability and performance remedies, but it does not establish the auditor's primary concern: the provider's obligation to protect data confidentiality, integrity and compliance. It is tempting because measurable service commitments feel like the strongest contractual safeguard, and it would be correct when availability is the dominant risk.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.