Certified Information Systems Auditor (CISA) — Question 929
A contract for outsourcing IS functions should always include:
Answer options
- A. a provision for an independent audit of the contractor's operations.
- B. data transfer protocols.
- C. the names and roles of staff to be employed in the operation.
- D. full details of security procedures to be observed by the contractor.
Correct answer: A
Explanation
Including a provision for an independent audit ensures that the contractor's operations can be evaluated for compliance and performance. While data transfer protocols and security procedures are important, they do not provide the same level of oversight as an independent audit. The names and roles of staff are relevant but do not guarantee operational integrity or accountability.