CISA - Information Systems Acquisition, Development and Implementation (12% of the exam) - Section 3.1

Assess system development methodologies and the identification and design of application controls.

Compare system development methodologies - including waterfall, agile and hybrid SDLC approaches - and explain how each affects control integration points. Apply control identification and control design principles to embed input, processing and output controls at appropriate stages of development.

system development methodologiesSDLCcontrol identificationcontrol design

Practice question for this objective

Free sampleInformation Systems Acquisition, Development and Implementationhard

An IS auditor is comparing the waterfall and agile development methodologies for a high-assurance billing rewrite. Which statement BEST describes how application controls are typically embedded under each approach?

  • AWaterfall defers control specification to user acceptance testing, while agile specifies controls during a dedicated hardening sprint at the end of the release.
  • BWaterfall and agile both defer control identification to the post-implementation review so that real production volumes can be observed.
  • CWaterfall captures controls within construction code reviews, while agile captures them in the project initiation document signed off by the steering committee.
  • DWaterfall embeds controls during the requirements and design phases, while agile relies on each iteration to refine controls as the product backlog evolves. Correct
Contrast how waterfall and agile methodologies sequence the identification and design of application controls across the development life cycle. Waterfall is a phase-gated methodology with a complete requirements and design baseline before construction begins, so application control requirements are captured and traced from those baselines. Agile relies on iterative refinement: each user story carries its own acceptance criteria, and control behaviour is added or adjusted as the backlog evolves, with the definition of done enforcing control coverage per increment.

Why A is wrong: This is tempting because both methodologies do test controls late, but waterfall actually specifies controls during the requirements and design phases up front, and agile distributes control work across iterations rather than waiting for a hardening sprint.

Why B is wrong: Candidates may select this because post-implementation review does evaluate control effectiveness, but neither methodology defers initial control identification to that point; controls must be designed in before deployment in any disciplined SDLC.

Why C is wrong: This reverses the typical pattern; waterfall captures control requirements before construction, and agile does not rely on a single up-front initiation document because requirements emerge across sprints.

Why D is correct: Waterfall produces a complete requirements and design baseline before construction, so control requirements are captured up front; agile defines acceptance criteria including controls per user story and refines them iteration by iteration as the backlog evolves.

See more CISA practice questions, answers explained.

Exam traps in Information Systems Acquisition, Development and Implementation

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISA bank for this domain.

  • Input controls such as field-level edit checks and dropdown enumerations on the order capture screens.

    Why it is wrong: Input controls are tempting because they govern data quality at entry, but they cannot demonstrate that totals reaching the general ledger match what the application processed during the day; they act at the wrong point in the transaction flow.

  • A detective control, because the limit check identifies the policy breach at the moment of data capture before posting.

    Why it is wrong: This option is tempting because the check does spot the breach, but a control that blocks the transaction at capture is preventive in classification, not detective; detective controls report after the event has already been recorded.

  • The developer who wrote and unit-tested the change is also responsible for promoting the build into the production environment at go-live.

    Why it is wrong: Allowing the developer to deploy their own build collapses preparation and execution into one role. Candidates pick this because it is operationally faster, but it breaks the classic preparation versus execution segregation.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.