CISA · Question #225
An IS auditor has found that a vendor has gone out of business and the escrow has an older version of the source code. What is the auditor's BEST recommendation for the organization?
The correct answer is A. Perform an analysis to determine the business risk.. The auditor's best first recommendation is to perform a business risk analysis to understand the potential impact of the outdated source code and vendor's dissolution.
Question
An IS auditor has found that a vendor has gone out of business and the escrow has an older version of the source code. What is the auditor's BEST recommendation for the organization?
Options
- APerform an analysis to determine the business risk.
- BDevelop a maintenance plan to support the application using the existing code.
- CBring the escrow version up to date.
- DAnalyze a new application that meets the current requirements.
How the community answered
(39 responses)- A67% (26)
- B5% (2)
- C10% (4)
- D18% (7)
Why each option
The auditor's best first recommendation is to perform a business risk analysis to understand the potential impact of the outdated source code and vendor's dissolution.
Before taking any specific action, the organization must understand the full scope of the problem. A business risk analysis will identify dependencies, potential operational disruptions, security vulnerabilities, compliance issues, and financial implications associated with the outdated source code and the absence of vendor support. This analysis provides the necessary information to make an informed decision on the most appropriate strategic response, which could involve options B, C, or D, or a combination.
Developing a maintenance plan is a potential solution, but it might not be feasible or the most cost-effective without first understanding the associated risks and the application's criticality.
Bringing the escrow version up to date could be an option, but it might be impossible or extremely costly without the vendor, and its necessity depends on the identified business risks.
Analyzing a new application is a significant undertaking and should only be considered after assessing the current application's risks and the viability of other solutions.
Concept tested: IS audit recommendations for vendor risk
Topics
Community Discussion
No community discussion yet for this question.