System Development and Implementation Flashcards
7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 System Development and Implementation flashcards as text
An IS auditor reviewing software procurement should FIRST verify that the vendor's product:
Answer: Meets the organization's defined functional and security requirements
Alignment with documented requirements is the foundational criterion before evaluating cost, market share, or technology features.
Which of the following BEST describes the purpose of a program change log?
Answer: To provide an audit trail of all modifications made to production programs
A program change log maintains a chronological record of who changed what and when, forming the audit trail for production program modifications.
During a SDLC audit, an IS auditor notices that requirements sign-off was obtained from IT management only, excluding business users. This represents a weakness in:
Answer: Requirements validation and stakeholder engagement
Requirements must be approved by business stakeholders who will use the system, not just IT, to ensure the solution meets actual business needs.
A software development team uses an iterative methodology where working software is delivered in short cycles. This BEST describes:
Answer: Agile/Scrum development
Agile/Scrum delivers working software in short, time-boxed sprints with frequent stakeholder feedback and iterative refinement.
When auditing a data conversion during system migration, the IS auditor should PRIMARILY verify that:
Answer: All data was accurately and completely transferred to the new system
Data integrity and completeness during conversion is critical; any data loss or corruption directly impacts business continuity and reliability of the new system.
An IS auditor finds that developers have direct access to the production environment. The MOST significant risk is:
Answer: Unauthorized or untested changes could be made directly to production
Direct developer access to production breaks segregation of duties and enables unauthorized modifications that bypass change control processes.
In software project management, a critical path PRIMARILY helps an IS auditor assess:
Answer: Which tasks, if delayed, will directly extend the project completion date
The critical path identifies the sequence of dependent tasks with zero float, meaning any delay on these tasks delays the entire project.