Which Process Best Ensures Vendor Software Remains Up to Date?

IT Audit & System Maintenance
Answer Correct answer: D — Implement structured release and patch management processes to systematically acquire, test, and deploy vendor updates while maintaining audit trails.

Which of the following provides the BEST assurance that vendor-supported software remains up to date?

  1. Software asset management
  2. Version management
  3. Licensing agreement and escrow
  4. Release and patch management Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of operational vs. administrative controls, with the common trap being confusion between version tracking (B) and active patch deployment (D).

Release and patch management is the critical IT audit control for maintaining vendor-supported software currency. This guide explains why structured update processes provide superior assurance over basic version tracking or asset inventories.

Option B (Version management) is frequently chosen because it sounds technical, but it only records installed versions without guaranteeing timely updates or vulnerability remediation.

Community Discussion (3 comments)

46080f2 👍 1 Selected: D
Release and patch management processes are explicitly designed to ensure software remains current by systematically obtaining vendor updates, testing them, and deploying patches through structured change control procedures1. This includes vulnerability scanning to confirm successful updates.
blehbleh 👍 1 Selected: D
Hayati, do you not research? Do you just try to memorize? It is D because if they are completing patches and managing patches then it will show they are staying up to date with patch management and versioning. Because if something is no longer supported the next “fix” for patches it to upgrade to the next version which can be seen in real life with rhel. They stop supporting older versions and when they do the vulnerabilities found in the old versions will state to mitigate these vulnerabilities you must update to the new version because in the new version they are realizing patches for the vulnerabilities.
Hayati 👍 1
Why not B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Release and patch management encompasses the end-to-end lifecycle of acquiring, validating, and deploying vendor updates. ISACA emphasizes that this process directly ensures systems remain aligned with current vendor support cycles and security baselines. By integrating vulnerability scanning and formal change control, auditors gain concrete evidence that software currency is actively maintained rather than passively recorded.

Why the Other Options Are Wrong

Software asset management focuses on inventory tracking and cost allocation, offering no mechanism for enforcing updates. Version management merely logs which builds are installed but does not mandate progression to supported releases or address emerging threats. Licensing agreements and escrow arrangements protect intellectual property rights and business continuity during vendor failure, completely unrelated to operational software freshness.

Community Comment Notes

Contributors consistently highlight that systematic update workflows serve as the definitive proof of currency, noting that real-world vendor support terminations force necessary upgrades. Some learners initially question version tracking, but experienced users clarify that version logging alone cannot verify whether teams actually apply vendor fixes or migrate away from end-of-life releases. As Hayati questioned, version management lacks the enforcement layer required to guarantee ongoing maintenance compliance.

Exam Strategy

When evaluating CISA maintenance questions, prioritize processes that involve active implementation and verification over passive tracking tools. Always look for the option that includes testing, deployment, and continuous monitoring of vendor updates.

Frequently Asked Questions

Why isn't version management sufficient for keeping software current?

Version management only logs installed builds. It lacks the enforcement mechanisms required to push vendor fixes, validate compatibility, or track end-of-support dates.

Does software asset management cover patching schedules?

No. SAM focuses on inventory, licensing, and cost optimization. Patch management handles the actual deployment and validation of vendor updates to maintain system currency.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide