Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An organization is selecting a vendor for a new procurement system. Which of the following is the MOST important factor to include in the contract?

⚠ Common exam trap

The trap is selecting options that seem important for contract management (e.g., SLAs, liability limits) but do not provide the organization with the ability to verify security controls; the exam expects you to prioritize the right to audit as a fundamental assurance mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Right to audit the vendor's security controls

The right to audit the vendor's security controls is the most important factor because it provides the organization with the ability to verify that the vendor is complying with security requirements and contractual obligations. Without this right, the organization has no assurance that its data is protected, especially when the vendor handles sensitive information. This is a critical governance and risk management control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A clause limiting vendor liability

    Why it's wrong here

    Liability caps transfer residual risk to the buyer and do nothing to prevent vendor failure; they belong in contracts where the buyer can absorb outages. The stem asks for the factor most critical to securing service delivery, which is measurable performance commitments, not financial risk allocation.

  • ✗

    Fixed price for the entire contract term

    Why it's wrong here

    A fixed price locks cost but provides no mechanism to enforce availability, response times or defect resolution. Pricing structures suit budget certainty; the stem's procurement system demands enforceable performance terms, so a fixed price addresses cost rather than the service outcomes the contract must guarantee.

  • ✗

    Detailed service level agreements (SLAs)

    Why it's wrong here

    SLAs govern ongoing performance, not the contractual protections a procurement selection needs, such as liability, data ownership and exit terms. They are tempting because availability and support metrics matter operationally, and SLAs would be the right focus when negotiating service commitments for an already-chosen vendor.

  • ✓

    Right to audit the vendor's security controls

    Why this is correct

    A contractual right to audit lets the organisation independently verify the vendor's security controls, rather than relying on self-attestation. This directly addresses the stem's constraint: the vendor will process organisational data, so the contract must preserve ongoing assurance over those controls.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.