Courseiva
hardMultiple Choice

Change Management in Waterfall: Impact Assessment and Prioritization

A multinational corporation is replacing its legacy on-premises customer relationship management (CRM) system with a new cloud-based CRM solution. The project involves migrating data from the old system, customizing the new system to match business processes, and integrating with an existing enterprise resource planning (ERP) system. The project has a tight deadline of six months. During the planning phase, the project team decides to use a waterfall methodology because the requirements are well-defined. However, three months into the project, the business users request significant changes to the customer data fields, which were not originally specified. The project manager is concerned that accommodating these changes will delay the project. The integration with the ERP system is also proving more complex than anticipated, with data mapping errors causing delays. The go-live date is fixed due to the end-of-support for the legacy system. What is the BEST course of action for the project manager?

Quick Answer

The correct answer is to conduct a formal change impact assessment and prioritize the changes, implementing only critical ones for the go-live. This is the best course of action because change management in waterfall project methodology requires a structured, gate-controlled process where any deviation from the approved baseline must be evaluated for its effect on scope, schedule, and cost before approval. In this scenario, with a fixed deadline driven by the legacy system’s end-of-support, a formal impact assessment allows the project manager to objectively weigh the requested data field changes against the integration delays, ensuring that only essential modifications are made to meet the go-live date. On the CISA exam, this question tests your understanding of the change control process within the IS acquisition and development domain, specifically how to balance business needs with project constraints in a waterfall lifecycle. A common trap is to immediately accept all changes to satisfy users or to reject them outright; instead, the exam emphasizes prioritization and deferral of non-critical enhancements. Memory tip: think “Assess, Prioritize, Defer” — like triage for project scope.

⚠ Common exam trap

Watch out — candidates often assume that switching to agile (Option D) is a flexible solution, but they overlook the fact that mid-project methodology changes are disruptive and rarely feasible within a fixed deadline, especially when the project has already invested heavily in waterfall artifacts and integration work.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a formal change impact assessment and prioritize the changes; implement only critical ones for go-live

It follows the structured change management process required in a waterfall project with a fixed deadline. By conducting a formal change impact assessment, the project manager can objectively evaluate the cost, schedule, and resource implications of the requested changes. Prioritizing only critical changes for go-live ensures that the core CRM functionality is delivered on time, while non-critical enhancements can be deferred to a post-implementation phase. This approach balances the need to meet the legacy system's end-of-support deadline with accommodating essential business requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conduct a formal change impact assessment and prioritize the changes; implement only critical ones for go-live

    Why this is correct

    A formal change impact assessment evaluates the requested customer data field changes against the fixed go-live date, letting the project manager accept only critical ones. This controls scope creep while preserving the waterfall baseline and the ERP integration work already underway.

  • ✗

    Inform the business users that no changes can be made due to the fixed deadline

    Why it's wrong here

    Refusing all changes ignores that the requested customer data fields may be business-critical, and the fixed date does not forbid re-prioritising scope. The project manager should assess and phase the changes, delivering essential fields at go-live and deferring the rest, rather than blocking users outright.

  • ✗

    Delay the go-live date to accommodate all changes and integration issues

    Why it's wrong here

    The go-live date is immovable because the legacy system's end-of-support cannot be extended, so delaying it leaves the business without a supported CRM. Schedule-driven projects with fixed deadlines instead reduce or phase scope, deferring the new data fields to a post-implementation release.

  • ✗

    Switch to an agile methodology for the remaining three months

    Why it's wrong here

    Switching methodology mid-project discards the completed waterfall baselines and re-planning overhead, consuming the three remaining months without addressing the fixed end-of-support date. Agile suits evolving requirements from project start; here the constraint is the immovable go-live, so scope must be prioritised instead.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During system implementation, a critical defect is found in the production environment. The project manager wants to apply an emergency patch without full testing. Which of the following is the BEST course of action?

hard
  • A.Apply the patch immediately without testing
  • B.Delay deployment until full testing can be completed
  • C.Revert to the previous version of the system
  • ✓ D.Conduct a risk assessment and obtain approval from the change control board

Why D: When a critical defect is found in production and an emergency patch is proposed without full testing, the BEST course of action is to conduct a risk assessment and obtain approval from the change control board (CAB). This ensures that the risk of applying an untested patch is formally evaluated, documented, and approved by the appropriate authority, balancing the need for a quick fix with proper change management controls. The CAB can also determine if emergency testing or a rollback plan is needed.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.