ExamGecko
Question list
Search
Search

Related questions

Question 1088 - CISA discussion

Report
Export

What should an IS auditor recommend to management as the MOST important action before selecting a Software as a Service (SaaS) vendor?

A.
Determine service level requirements.
Answers
A.
Determine service level requirements.
B.
Complete a risk assessment.
Answers
B.
Complete a risk assessment.
C.
Perform a business impact analysis (BIA)
Answers
C.
Perform a business impact analysis (BIA)
D.
Conduct a vendor audit.
Answers
D.
Conduct a vendor audit.
Suggested answer: B

Explanation:

Before selecting a SaaS vendor, the most important action is to complete a risk assessment. A risk assessment is a process of identifying, analyzing, and evaluating the potential risks associated with outsourcing software and IT infrastructure to a third-party provider. A risk assessment helps to determine the impact and likelihood of various threats, such as data breaches, service disruptions, vendor lock-in, compliance issues, and legal disputes. A risk assessment also helps to identify the mitigation strategies and controls that can reduce or eliminate the risks.

A risk assessment is more important than determining service level requirements, performing a business impact analysis (BIA), or conducting a vendor audit because it provides the basis for these other actions. Service level requirements are the expectations and obligations that define the quality and quantity of service that the vendor must provide to the customer. A BIA is a process of assessing the potential effects of an interruption or disruption of critical business functions or processes due to an incident or disaster. A vendor audit is a process of verifying the vendor's compliance with the contract terms, service levels, security policies, and best practices.

Service level requirements, BIA, and vendor audit are all important actions for selecting a SaaS vendor, but they depend on the results of the risk assessment. For example, service level requirements should reflect the risk appetite and tolerance of the customer, which are determined by the risk assessment. A BIA should prioritize the recovery of the most critical and vulnerable business functions or processes, which are identified by the risk assessment. A vendor audit should focus on the areas of highest risk and concern, which are highlighted by the risk assessment.

Therefore, an IS auditor should recommend to management that completing a risk assessment is the most important action before selecting a SaaS vendor.

SaaS checklist: Nine factors to consider when selecting a vendor

SaaS vendor management: 10 best practices to achieve success

Best Practices for Software SaaS Vendor Selection and Negotiation

How to Evaluate SaaS Providers and Solutions by Developing ... - Gartner

asked 18/09/2024
hesham azarkan
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first