CISA Governance and Management of IT Practice Question
An organization is planning to outsource its data center operations. Which of the following governance practices should be implemented to ensure proper oversight?
⚠ Common exam trap
The trap is selecting a specific certification or audit as the primary governance practice, when the broader and more essential practice is establishing measurable SLAs with KPIs for ongoing oversight.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establish a service level agreement (SLA) with key performance indicators (KPIs).
Establishing an SLA with KPIs is a fundamental governance practice for outsourcing because it defines measurable performance expectations and provides a basis for monitoring and enforcing the provider's obligations. It ensures the outsourcer is accountable for service delivery and aligns with business objectives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct annual financial audits of the outsourcer.
Why it's wrong here
Financial audits examine the outsourcer's accounts, not security controls, service levels or data handling, so they provide no operational oversight. They are tempting because they are a familiar assurance mechanism, and they would be appropriate for verifying billing accuracy or the provider's financial stability.
- ✗
Require the outsourcer to obtain ISO 27001 certification.
Why it's wrong here
ISO 27001 certifies the outsourcer's management system at a point in time; it does not give the organisation ongoing visibility, audit rights or control over its own data. It is tempting because certification is an easy due-diligence signal, suitable for pre-contract vendor screening rather than continuous governance.
- ✓
Establish a service level agreement (SLA) with key performance indicators (KPIs).
Why this is correct
An SLA with KPIs defines measurable performance targets and remedies, giving the organisation contractual oversight of the outsourced data centre. It satisfies the governance constraint by establishing enforceable accountability, monitoring and reporting rather than relying on the vendor's internal controls alone.
- ✗
Allow the outsourcer to manage all security controls independently.
Why it's wrong here
Granting the outsourcer full control removes the organisation's ability to monitor, approve changes and enforce contractual security obligations, defeating oversight. It is tempting because it minimises internal effort and clarifies accountability, which suits commodity services where the provider is wholly trusted and no sensitive data is involved.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.