CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An organization is selecting a vendor for a new procurement system. Which of the following is the MOST important factor to include in the contract?
⚠ Common exam trap
The trap is selecting options that seem important for contract management (e.g., SLAs, liability limits) but do not provide the organization with the ability to verify security controls; the exam expects you to prioritize the right to audit as a fundamental assurance mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Right to audit the vendor's security controls
The right to audit the vendor's security controls is the most important factor because it provides the organization with the ability to verify that the vendor is complying with security requirements and contractual obligations. Without this right, the organization has no assurance that its data is protected, especially when the vendor handles sensitive information. This is a critical governance and risk management control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A clause limiting vendor liability
Why it's wrong here
Liability caps transfer residual risk to the buyer and do nothing to prevent vendor failure; they belong in contracts where the buyer can absorb outages. The stem asks for the factor most critical to securing service delivery, which is measurable performance commitments, not financial risk allocation.
- ✗
Fixed price for the entire contract term
Why it's wrong here
A fixed price locks cost but provides no mechanism to enforce availability, response times or defect resolution. Pricing structures suit budget certainty; the stem's procurement system demands enforceable performance terms, so a fixed price addresses cost rather than the service outcomes the contract must guarantee.
- ✗
Detailed service level agreements (SLAs)
Why it's wrong here
SLAs govern ongoing performance, not the contractual protections a procurement selection needs, such as liability, data ownership and exit terms. They are tempting because availability and support metrics matter operationally, and SLAs would be the right focus when negotiating service commitments for an already-chosen vendor.
- ✓
Right to audit the vendor's security controls
Why this is correct
A contractual right to audit lets the organisation independently verify the vendor's security controls, rather than relying on self-attestation. This directly addresses the stem's constraint: the vendor will process organisational data, so the contract must preserve ongoing assurance over those controls.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.