The correct answer is B. Ensuring vendor default accounts and passwords have been disabled.
When implementing a new cloud-based application, the first priority is to ensure the system is securely configured before it goes live. Vendor default accounts and default passwords are well-known security weaknesses because attackers often try default credentials first. For a cloud-based application, this risk is especially important because SaaS and cloud services are commonly exposed through the Internet, increasing the risk of credential-based attacks and account takeover. ISACA discusses SaaS account-takeover risk and notes that SaaS exposure to the Internet creates opportunities for credential-based attacks.
Option A is not the best answer because, in a cloud-based vendor application, the customer usually does not control the vendor’s source code. Option C is not first because maintenance agreement compliance is normally reviewed after service operation begins or during vendor management reviews. Option D is not relevant because escrow normally applies to source code or software ownership/continuity arrangements, and SaaS customers often do not hold or manage old program copies.
This question maps to Information Systems Acquisition, Development and Implementation because it concerns secure system implementation, vendor-provided systems, and readiness before production use. ISACA’s CISA Exam Content Outline includes system development/acquisition, implementation readiness, and implementation testing under Domain 3.
[References: ISACA CISA Exam Content Outline, Domain 3; ISACA article, SaaS Security Risk and Challenges., ===================, ]
Submit