CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An organization is planning to purchase a cloud-based HR system. Which THREE of the following should be included in the vendor contract to ensure adequate control and oversight? (Select three.)
⚠ Common exam trap
The ISACA CISA exam often emphasizes the importance of contractual clauses that provide direct oversight and enforceability, such as right to audit and SLAs, rather than items that only offer transparency or commercial terms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Right to audit the vendor's controls
Option B is correct because a right-to-audit clause contractually guarantees the organization can assess the vendor's security controls, either directly or via a third-party assessment such as SOC 2, which is essential for ongoing oversight of a cloud HR system holding sensitive employee data. Option C is correct because an SLA defining uptime and response times establishes measurable performance and availability commitments, giving the organization enforceable remedies if service levels are missed. Option E is correct because data ownership and data protection clauses clarify that the organization retains ownership of its HR data and obligate the vendor to safeguard it in line with applicable privacy and security requirements. Option A is not among the marked answers, and while subprocessor transparency is useful, it is not one of the three required contract elements here. Option D is not marked because a fixed-price payment schedule addresses commercial cost certainty, not control and oversight of the vendor's security and service performance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A list of all subprocessors
Why it's wrong here
A subprocessor list is a transparency disclosure, not a contractual control mechanism; it does not itself impose audit rights, data-residency limits or breach notification on the vendor. It is tempting because supply-chain visibility is a genuine due-diligence artefact, and would be the right answer to a question asking what to request during vendor assessment.
- ✓
Right to audit the vendor's controls
Why this is correct
A right-to-audit clause grants the organisation contractual authority to examine the vendor's control environment, satisfying the oversight requirement for a cloud-hosted HR system holding sensitive employee data. Without it, assurance relies solely on vendor self-reporting, such as SOC 2 reports, which cannot be independently verified or scoped to the organisation's specific compliance obligations.
- ✓
Service-level agreement (SLA) specifying uptime and response times
Why this is correct
An SLA contractually binds the vendor to measurable uptime and response-time commitments, directly satisfying the oversight requirement for a cloud-hosted HR system where the organisation surrenders direct infrastructure control. It establishes enforceable performance thresholds and remedies, enabling continuous monitoring of availability and support responsiveness rather than relying on vendor assurances.
- ✗
A fixed-price payment schedule
Why it's wrong here
A fixed-price schedule addresses commercial cost certainty, not the control and oversight objectives such as audit rights, data protection or service levels that the contract must secure. It is tempting because pricing terms are a standard contract component, and would be correct if the question asked how to cap project expenditure.
- ✓
Data ownership and data protection clauses
Why this is correct
Data ownership clauses establish that the organisation, not the vendor, retains legal title to HR data, while protection clauses impose GDPR-aligned processing, breach notification and retention duties. Together they satisfy the stem's oversight requirement by binding the vendor contractually to safeguard confidentiality and return or delete data on termination.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.