Actual CISA Domain 4 Review Questions, Answers
& Explanations Manual, 12th Edition Test Bank
Recently Updated Complete Solution
Save
Terms in this set (258)
, C is the correct answer. Justification:
A. A due diligenceactivitysuch as
reviewingreferencesfrom otherclientsis a good
practice,but the service level agreement(SLA)
A4-1 An organization is wouldbe most criticalbecauseit woulddefine what
considering using a new IT specificlevelsof performance wouldbe requiredand
service provider. From an make the providercontractuallyobligatedto
audit perspective, which deliverwhat was promised.
of the following would be B. A due diligence activity such as reviewing physical
the MOST important item security controls is a good practice, but the SLA
to review? would be most critical because it would define what
specific levels of security would be required and
A. References from other make the provider contractually obligated to deliver
clients for the service what was promised.
provider C. When contracting with a service provider, it is a
B. The physical security of good practice to enter into an SLA with the
the service provider site provider. An SLA is a guarantee that the provider will
C. The proposed service deliver the services according to the contract. The IS
level agreement with the auditor will want to ensure that performance and
service provider security requirements are clearly stated in the SLA.
D. Background checks of D. A due diligence activity such as the use of
the service provider's background checks for the service provider's
employees employees is a good practice, but the SLA would be
most critical because it would define what specific
levels of security and labor practices would be
required and make the provider contractually
obligated to deliver what was promised.
,A4-2 An IS auditor is to A is the correct answer. Justification:
assess the suitability of a A. The delivery of IT services for a specific customer
service level agreement always implies a dose linkage between the
(SLA) between the client and the supplier of the service. If there are no
organization and the contract terms to specify how the transition to a new
supplier of outsourced supplier may be performed, there is the risk that the
services. To which of the old supplier may simply "pull the plug" if the contract
following observations expires or is terminated or may not make data
should the IS auditor pay available to the outsourcing organization or new
the MOST attention? The supplier. This would be the greatest risk to the
SLA does not contain a: organization.
B. Contractual issues regarding payment, service
A. transition clauses from improvement and dispute resolution are important but
the old supplier to a new not as critical as ensuring that service disruption, data
supplier or back to loss, data retention, or other significant events occur
internal in the case of in the event that the organization switches to a new
expiration or termination. firm providing outsourced services.
B. late payment clause C. The service level agreement (SLA) should address
between the customer performance requirements and metrics to report on
and the supplier. the status of services provided; it's nice to have
C. contractual commitment for performance improvement, although
commitment for service it's not mandated.
improvement. D. The SLA should address a dispute resolution
D. dispute resolution procedure and specify the jurisdiction in case of a
procedure between the legal dispute, but this is not the most critical part of an
contracting parties. SLA.
, A is the correct answer. Justification:
A. The absence of a "right to audit" clause or other
form of attestation that the supplier was compliant
with a certain standard would potentially prevent the
IS auditor from investigating any aspect of supplier
performance moving forward, including control
A4-3 An IS auditor
deficiencies, poor performance and adherence to
reviewing a new
legal requirements. This would be a major concern for
outsourcing contract with
the IS auditor because it would be difficult for the
a service provider would
organization to assess whether the appropriate
be MOST concerned if
controls had been put in place.
which of the following was
B. While a clear definition of penalty payment terms is
missing?
desirable, not all contracts require the payment of
penalties for poor performance, and when
A. A clause providing a
performance penalties are required, these penalties
"right to audit" the service
are often subject to negotiation on a case-by-case
provider
basis. As such, the absence of this information would
B. A clause defining
not be
penalty payments for poor
as significant as a lack of right to audit.
performance
C. While the inclusion of service level report
C. Predefined service
templates would be desirable, as long as the
level report templates
requirement for service level reporting is included in
D. A clause regarding
the contract, the absence of predefined templates for
supplier limitation of
reporting is not a significant concern.
liability
D. The absence of a limitation of liability clause for the
service provider would, theoretically, expose the
provider to unlimited liability. This would be to the
advantage of the outsourcing company so, while the
IS auditor might highlight the absence of such a
clause, it would not constitute a major concern.
& Explanations Manual, 12th Edition Test Bank
Recently Updated Complete Solution
Save
Terms in this set (258)
, C is the correct answer. Justification:
A. A due diligenceactivitysuch as
reviewingreferencesfrom otherclientsis a good
practice,but the service level agreement(SLA)
A4-1 An organization is wouldbe most criticalbecauseit woulddefine what
considering using a new IT specificlevelsof performance wouldbe requiredand
service provider. From an make the providercontractuallyobligatedto
audit perspective, which deliverwhat was promised.
of the following would be B. A due diligence activity such as reviewing physical
the MOST important item security controls is a good practice, but the SLA
to review? would be most critical because it would define what
specific levels of security would be required and
A. References from other make the provider contractually obligated to deliver
clients for the service what was promised.
provider C. When contracting with a service provider, it is a
B. The physical security of good practice to enter into an SLA with the
the service provider site provider. An SLA is a guarantee that the provider will
C. The proposed service deliver the services according to the contract. The IS
level agreement with the auditor will want to ensure that performance and
service provider security requirements are clearly stated in the SLA.
D. Background checks of D. A due diligence activity such as the use of
the service provider's background checks for the service provider's
employees employees is a good practice, but the SLA would be
most critical because it would define what specific
levels of security and labor practices would be
required and make the provider contractually
obligated to deliver what was promised.
,A4-2 An IS auditor is to A is the correct answer. Justification:
assess the suitability of a A. The delivery of IT services for a specific customer
service level agreement always implies a dose linkage between the
(SLA) between the client and the supplier of the service. If there are no
organization and the contract terms to specify how the transition to a new
supplier of outsourced supplier may be performed, there is the risk that the
services. To which of the old supplier may simply "pull the plug" if the contract
following observations expires or is terminated or may not make data
should the IS auditor pay available to the outsourcing organization or new
the MOST attention? The supplier. This would be the greatest risk to the
SLA does not contain a: organization.
B. Contractual issues regarding payment, service
A. transition clauses from improvement and dispute resolution are important but
the old supplier to a new not as critical as ensuring that service disruption, data
supplier or back to loss, data retention, or other significant events occur
internal in the case of in the event that the organization switches to a new
expiration or termination. firm providing outsourced services.
B. late payment clause C. The service level agreement (SLA) should address
between the customer performance requirements and metrics to report on
and the supplier. the status of services provided; it's nice to have
C. contractual commitment for performance improvement, although
commitment for service it's not mandated.
improvement. D. The SLA should address a dispute resolution
D. dispute resolution procedure and specify the jurisdiction in case of a
procedure between the legal dispute, but this is not the most critical part of an
contracting parties. SLA.
, A is the correct answer. Justification:
A. The absence of a "right to audit" clause or other
form of attestation that the supplier was compliant
with a certain standard would potentially prevent the
IS auditor from investigating any aspect of supplier
performance moving forward, including control
A4-3 An IS auditor
deficiencies, poor performance and adherence to
reviewing a new
legal requirements. This would be a major concern for
outsourcing contract with
the IS auditor because it would be difficult for the
a service provider would
organization to assess whether the appropriate
be MOST concerned if
controls had been put in place.
which of the following was
B. While a clear definition of penalty payment terms is
missing?
desirable, not all contracts require the payment of
penalties for poor performance, and when
A. A clause providing a
performance penalties are required, these penalties
"right to audit" the service
are often subject to negotiation on a case-by-case
provider
basis. As such, the absence of this information would
B. A clause defining
not be
penalty payments for poor
as significant as a lack of right to audit.
performance
C. While the inclusion of service level report
C. Predefined service
templates would be desirable, as long as the
level report templates
requirement for service level reporting is included in
D. A clause regarding
the contract, the absence of predefined templates for
supplier limitation of
reporting is not a significant concern.
liability
D. The absence of a limitation of liability clause for the
service provider would, theoretically, expose the
provider to unlimited liability. This would be to the
advantage of the outsourcing company so, while the
IS auditor might highlight the absence of such a
clause, it would not constitute a major concern.