Mitigating SaaS Provider Bankruptcy Risk
Which of the following is the BEST way to mitigate the risk of services no longer being available from a bankrupt Software as a Service (SaaS) provider?
Community Votes
50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests cloud risk mitigation by contrasting SaaS architecture limitations with traditional on-premise solutions, where the common trap is choosing software escrow despite customers lacking source code access.
This CISA question tests strategies for maintaining business continuity when a SaaS vendor faces financial failure. While some candidates debate software escrow, experts and community consensus agree that backing up critical data is the most practical and effective mitigation.
Option C (software escrow) is frequently chosen because it works for proprietary on-premise software, but it fails here since SaaS customers never receive or control the underlying application source code.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Backing up critical data directly addresses the primary operational risk when a SaaS vendor becomes insolvent. Since SaaS architecture centralizes application hosting, organizations retain responsibility for data protection and portability. Implementing regular backups ensures that essential business records survive service termination, enabling immediate recovery or migration to an alternative platform. This aligns with ISACA’s guidance on cloud data governance and business continuity planning.Why the Other Options Are Wrong
Service level agreements merely establish performance metrics during active contracts and offer zero legal leverage during insolvency proceedings. Retaining local software copies contradicts the fundamental SaaS model, where applications run exclusively on the provider’s infrastructure. Software escrow agreements require contractual source code release rights, which subscription-based SaaS customers inherently lack. Consequently, these options either misalign with cloud service definitions or fail to address actual data retention needs.Community Comment Notes
Top-voted discussions highlight that escrow mechanisms apply to proprietary on-premise deployments, not cloud subscriptions. As contributor #2 notes, SaaS licensing grants usage rights rather than source code access, making escrow legally unenforceable. Multiple commenters reinforce that focusing on data portability rather than application ownership reflects real-world cloud risk management. This consensus directly validates why data backup remains the definitive exam answer.Official Reference
Exam Strategy
Always distinguish between SaaS, PaaS, and IaaS ownership models before selecting risk mitigation options. In SaaS scenarios, focus exclusively on data portability and backup rather than application-level controls like source code escrow.
Frequently Asked Questions
Why isn't software escrow appropriate for SaaS?
Escrow requires sharing source code, which SaaS vendors never provide to subscribers. Customers only license usage rights, making escrow legally and technically unfeasible.
Do SLAs protect against vendor bankruptcy?
No. SLAs define uptime and performance targets during normal operations but cannot enforce service delivery once a company ceases financial existence.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →