CISA Question of the Day: Source Code Escrow Evaluation

CISA exam practice question — CISA Question of the Day: Source Code Escrow Evaluation

CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Acquisition, Development and Implementation.

Question

A company is procuring a critical third‑party application. During the auditor's acquisition review, which action is most appropriate to assess whether source code escrow arrangements adequately protect continuity of service?

  • A. Request direct access to the vendor’s active source code repository and perform code buildability and security checks
  • B. Obtain and assess the source code escrow agreement to confirm defined release triggers, included build instructions, verification procedures and periodic retrieval testing
  • C. Accept the vendor’s written attestation that source code is maintained and will be released under contract terms without further verification
  • D. Verify the contract contains indemnity and confidentiality clauses related to intellectual property and defer technical escrow testing to post‑delivery operations
Show the answer and explanation

Correct answer: B. Obtain and assess the source code escrow agreement to confirm defined release triggers, included build instructions, verification procedures and periodic retrieval testing

The best audit action is to obtain and assess the escrow agreement to ensure it defines release triggers, includes build instructions and verification procedures, and requires periodic retrieval testing. This provides reasonable assurance that the client can rebuild and maintain the system if the vendor cannot support it. Requesting direct access to the vendor’s repository is often impractical, legally sensitive, and beyond what’s needed to evaluate escrow adequacy. Accepting a vendor attestation without independent verification is insufficient because attestations may not reflect actual escrow content or test results. Relying solely on indemnity/confidentiality clauses and deferring technical testing leaves continuity risks untested and unresolved.

Want more practice?

Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.