nerdexam
Isaca

CISA · Question #49

An IS auditor is reviewing a contract for the outsourcing of IT facilities. If missing, which of the following should present the GREATEST concern to the auditor?

The correct answer is A. Access control requirements. The greatest concern for an IS auditor reviewing an outsourced IT facilities contract is the absence of explicit access control requirements, as this directly impacts the security of the hosted environment.

Submitted by mike_84· Apr 18, 2026Governance and Management of IT

Question

An IS auditor is reviewing a contract for the outsourcing of IT facilities. If missing, which of the following should present the GREATEST concern to the auditor?

Options

  • AAccess control requirements
  • BHardware configurations
  • CHelp desk availability
  • DPerimeter network security diagram

How the community answered

(38 responses)
  • A
    47% (18)
  • B
    29% (11)
  • C
    8% (3)
  • D
    16% (6)

Why each option

The greatest concern for an IS auditor reviewing an outsourced IT facilities contract is the absence of explicit access control requirements, as this directly impacts the security of the hosted environment.

AAccess control requirementsCorrect

Access control requirements are fundamental to securing any IT facility, especially an outsourced one, as they dictate who can physically and logically access the systems and data. Without clear contractual stipulations for access control, the organization loses critical oversight and assurance over the security of its outsourced environment, which presents the greatest security risk.

BHardware configurations

While hardware configurations are important, they can often be detailed in appendices or separate documentation and are a consequence of security policy, whereas access control is a foundational and direct security requirement.

CHelp desk availability

Help desk availability is an operational service level agreement (SLA) concern, impacting support and business continuity, but it does not directly relate to the foundational security of the IT facilities themselves.

DPerimeter network security diagram

A perimeter network security diagram is a technical detail that illustrates one aspect of security; however, robust access control policies are a broader and more fundamental security requirement, encompassing both physical and logical access throughout the facility.

Concept tested: Outsourcing contract security requirements

Source: https://www.isaca.org/resources/isaca-journal/isaca-journal-archives/2014/volume-5/outsourcing-and-third-party-risk-management

Topics

#Outsourcing contract#Access control#IS audit#Vendor management

Community Discussion

No community discussion yet for this question.

Full CISA Practice