What action can help mitigate the risk of continued support for a third-party application?

Prepare for the CISA Domain 5 Exam with our quizzes. Engage with flashcards, multiple-choice questions, detailed hints, and explanations. Boost your confidence and get ready to succeed!

The selection of a software escrow agreement is a robust strategy for mitigating the risks associated with the continued support of a third-party application. A software escrow agreement involves placing the source code of the application into a third-party escrow service. This means that if the vendor fails to maintain the application or goes out of business, you have access to the source code and can ensure the application continues to function or be maintained.

By having the source code available, an organization can take the necessary steps to sustain the software, including the potential of modifying it to meet ongoing needs. This is particularly significant in risk management as it provides a safety net that ensures the organization's investment in the third-party application can be preserved in the face of vendor-related issues.

Other options, while they may contribute to a broader risk assessment strategy, do not directly address the issue of continued support in the same manner. A financial evaluation of the vendor may help assess current stability but does not directly provide assurance for future support. A viability study may assess the vendor's capability but lacks the security of access to code if things go awry. Lastly, a contractual agreement for future enhancements focuses on future upgrades and features, but it does not guarantee that the vendor will be available to provide those enhancements when needed

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy