CISA - Information Systems Acquisition, Development and Implementation - Section 3.1

Assess system development methodologies and the identification and design of application controls.

Compare system development methodologies - including waterfall, agile and hybrid SDLC approaches - and explain how each affects control integration points. Apply control identification and control design principles to embed input, processing and output controls at appropriate stages of development.

system development methodologiesSDLCcontrol identificationcontrol design

Practice question for this objective

Free sampleInformation Systems Acquisition, Development and Implementationhard

An IS auditor is comparing the waterfall and agile development methodologies for a high-assurance billing rewrite. Which statement BEST describes how application controls are typically embedded under each approach?

  • AWaterfall defers control specification to user acceptance testing, while agile specifies controls during a dedicated hardening sprint at the end of the release.
  • BWaterfall and agile both defer control identification to the post-implementation review so that real production volumes can be observed.
  • CWaterfall captures controls within construction code reviews, while agile captures them in the project initiation document signed off by the steering committee.
  • DWaterfall embeds controls during the requirements and design phases, while agile relies on each iteration to refine controls as the product backlog evolves. Correct
Contrast how waterfall and agile methodologies sequence the identification and design of application controls across the development life cycle. Waterfall is a phase-gated methodology with a complete requirements and design baseline before construction begins, so application control requirements are captured and traced from those baselines. Agile relies on iterative refinement: each user story carries its own acceptance criteria, and control behaviour is added or adjusted as the backlog evolves, with the definition of done enforcing control coverage per increment.

Why A is wrong: This is tempting because both methodologies do test controls late, but waterfall actually specifies controls during the requirements and design phases up front, and agile distributes control work across iterations rather than waiting for a hardening sprint.

Why B is wrong: Candidates may select this because post-implementation review does evaluate control effectiveness, but neither methodology defers initial control identification to that point; controls must be designed in before deployment in any disciplined SDLC.

Why C is wrong: This reverses the typical pattern; waterfall captures control requirements before construction, and agile does not rely on a single up-front initiation document because requirements emerge across sprints.

Why D is correct: Waterfall produces a complete requirements and design baseline before construction, so control requirements are captured up front; agile defines acceptance criteria including controls per user story and refines them iteration by iteration as the backlog evolves.

See more CISA practice questions, answers explained.

More in this domain

Back to all Information Systems Acquisition, Development and Implementation objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.