nerdexam
Isaca

CISA · Question #225

An IS auditor has found that a vendor has gone out of business and the escrow has an older version of the source code. What is the auditor's BEST recommendation for the organization?

The correct answer is A. Perform an analysis to determine the business risk.. The auditor's best first recommendation is to perform a business risk analysis to understand the potential impact of the outdated source code and vendor's dissolution.

Submitted by mateo_ar· Apr 18, 2026Information Systems Acquisition, Development, and Implementation

Question

An IS auditor has found that a vendor has gone out of business and the escrow has an older version of the source code. What is the auditor's BEST recommendation for the organization?

Options

  • APerform an analysis to determine the business risk.
  • BDevelop a maintenance plan to support the application using the existing code.
  • CBring the escrow version up to date.
  • DAnalyze a new application that meets the current requirements.

How the community answered

(39 responses)
  • A
    67% (26)
  • B
    5% (2)
  • C
    10% (4)
  • D
    18% (7)

Why each option

The auditor's best first recommendation is to perform a business risk analysis to understand the potential impact of the outdated source code and vendor's dissolution.

APerform an analysis to determine the business risk.Correct

Before taking any specific action, the organization must understand the full scope of the problem. A business risk analysis will identify dependencies, potential operational disruptions, security vulnerabilities, compliance issues, and financial implications associated with the outdated source code and the absence of vendor support. This analysis provides the necessary information to make an informed decision on the most appropriate strategic response, which could involve options B, C, or D, or a combination.

BDevelop a maintenance plan to support the application using the existing code.

Developing a maintenance plan is a potential solution, but it might not be feasible or the most cost-effective without first understanding the associated risks and the application's criticality.

CBring the escrow version up to date.

Bringing the escrow version up to date could be an option, but it might be impossible or extremely costly without the vendor, and its necessity depends on the identified business risks.

DAnalyze a new application that meets the current requirements.

Analyzing a new application is a significant undertaking and should only be considered after assessing the current application's risks and the viability of other solutions.

Concept tested: IS audit recommendations for vendor risk

Topics

#Source Code Escrow#Vendor Management#Business Risk Assessment#Application Lifecycle

Community Discussion

No community discussion yet for this question.

Full CISA Practice