Courseiva

CRISC Information Technology and Security Practice Question

A healthcare organization is migrating its electronic health records (EHR) to a SaaS provider. The provider offers a standard contract with a 99.9% uptime SLA but no right to audit. The risk manager is concerned about data integrity and availability. Which of the following is the BEST risk response to address the lack of audit rights?

⚠ Common exam trap

The trap here is assuming that an uptime SLA or cyber insurance adequately addresses the risk of not having audit rights, when the core issue is lack of assurance over the provider's security controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Negotiate a contract amendment to include audit rights or obtain independent third-party attestations such as SOC 2 Type II reports.

The best response is to obtain assurance through contractual audit rights or independent attestations like SOC 2 Type II. This directly addresses the lack of visibility into the provider's controls, which is critical for data integrity and compliance. Other options either accept the risk without assurance, implement costly redundancies that do not solve the problem, or transfer financial risk without addressing the control gap.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transfer the risk by purchasing cyber insurance that covers data breaches at the SaaS provider.

    Why it's wrong here

    Cyber insurance can transfer financial impact but does not provide assurance that the provider's controls are effective. It does not address the root cause of the risk—lack of visibility into the provider's environment. Insurance is a complementary risk response, not a substitute for due diligence and contractual protections, especially for regulatory compliance.

  • ✗

    Implement a redundant on-premises EHR system to mitigate the risk of provider failure.

    Why it's wrong here

    Implementing a redundant on-premises system is costly, complex, and may not address the lack of audit rights for the SaaS provider. It introduces data synchronization challenges and potential inconsistencies. While it improves availability, it does not provide assurance over the provider's security controls, leaving data integrity and confidentiality risks unaddressed.

  • ✓

    Negotiate a contract amendment to include audit rights or obtain independent third-party attestations such as SOC 2 Type II reports.

    Why this is correct

    Negotiating audit rights or accepting independent attestations like SOC 2 Type II provides assurance over the provider's controls without direct auditing. SOC 2 reports cover security, availability, and confidentiality, which are critical for EHR data. This is a practical risk response that balances assurance with vendor relationships, reducing risk to an acceptable level while maintaining compliance with regulations like HIPAA.

  • ✗

    Accept the risk because the SLA guarantees uptime and the provider is reputable.

    Why it's wrong here

    Accepting the risk based solely on reputation and an uptime SLA ignores the need for assurance over data integrity and security controls. Uptime does not cover data breaches, unauthorized access, or compliance violations. Without audit rights, the organization cannot verify the provider's controls, leaving significant residual risk that may not be acceptable for protected health information.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.