CISA · Question #503
An organization's email service is hosted by a third party, and the service level agreement (SLA) requires 99.9% availability. An IS auditor finds that the service has not met its availability level f
The correct answer is C. Review the service provider relationship and consider alternatives.. Reviewing the provider relationship and considering alternatives is the most balanced and professionally sound recommendation because an IS auditor's role is to assess risk and guide decision-making - not to take drastic unilateral action without proper due diligence. Five months
Question
An organization's email service is hosted by a third party, and the service level agreement (SLA) requires 99.9% availability. An IS auditor finds that the service has not met its availability level for the past five months. Which of the following is the auditor's BEST recommendation?
Options
- ASelf-host an email server and monitor availability.
- BWithhold payment until availability service level is met.
- CReview the service provider relationship and consider alternatives.
- DDiscontinue use of the email service provider.
How the community answered
(17 responses)- B6% (1)
- C82% (14)
- D12% (2)
Explanation
Reviewing the provider relationship and considering alternatives is the most balanced and professionally sound recommendation because an IS auditor's role is to assess risk and guide decision-making - not to take drastic unilateral action without proper due diligence. Five months of SLA breaches signals a systemic issue that warrants evaluating whether to renegotiate terms, escalate contractually, or migrate to a better provider.
Why the distractors are wrong:
- A - Self-hosting introduces new risks, costs, and complexity; it's a major architectural decision that shouldn't be the auditor's first recommendation without a thorough analysis.
- B - Withholding payment may violate the contract itself and could escalate legal issues rather than resolve the availability problem.
- D - Immediately discontinuing the service is too drastic and disruptive without first evaluating alternatives and transition plans; it could cause more downtime than the SLA breach already has.
Memory tip: Think of the IS auditor as a navigator, not a captain - they recommend courses of action based on evidence, not make impulsive operational decisions. "Review and consider" reflects measured, risk-aware guidance, which is always preferred over reactive extremes (withhold, discontinue) or premature solutions (self-host).
Topics
Community Discussion
No community discussion yet for this question.