
CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Acquisition, Development and Implementation.
Question
A company is procuring a critical third‑party application. During the auditor's acquisition review, which action is most appropriate to assess whether source code escrow arrangements adequately protect continuity of service?
Show the answer and explanation
Correct answer: B. Obtain and assess the source code escrow agreement to confirm defined release triggers, included build instructions, verification procedures and periodic retrieval testing
The best audit action is to obtain and assess the escrow agreement to ensure it defines release triggers, includes build instructions and verification procedures, and requires periodic retrieval testing. This provides reasonable assurance that the client can rebuild and maintain the system if the vendor cannot support it. Requesting direct access to the vendor’s repository is often impractical, legally sensitive, and beyond what’s needed to evaluate escrow adequacy. Accepting a vendor attestation without independent verification is insufficient because attestations may not reflect actual escrow content or test results. Relying solely on indemnity/confidentiality clauses and deferring technical testing leaves continuity risks untested and unresolved.
Want more practice?
Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.
