CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An IS auditor is reviewing a project that is developing a new customer relationship management (CRM) system using the Agile Scrum framework. The project team has completed several sprints, and the product owner has accepted the increments. The auditor wants to ensure that the system will meet the organization's security requirements before go-live. Which of the following is the MOST effective way for the auditor to achieve this?
⚠ Common exam trap
The trap here is assuming that security is automatically covered by functional acceptance or that a final security assessment is sufficient, when in Agile it must be integrated into each sprint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the user stories and acceptance criteria to verify that security requirements are included and tested in each sprint.
In Agile Scrum, security requirements should be treated as backlog items and tested within sprints to ensure continuous validation. The most effective audit approach is to examine user stories and acceptance criteria for security content and evidence of testing. This provides real-time assurance that security is being addressed, rather than relying on post-hoc assessments or high-level plans. Thus, reviewing user stories and acceptance criteria is the correct approach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify that the product owner has signed off on all functional requirements, as this ensures security is also covered.
Why it's wrong here
Functional sign-off does not guarantee that security requirements have been addressed. Security is a non-functional requirement that must be explicitly defined and tested. The product owner's acceptance of functional increments does not imply security validation. This option is incorrect because it assumes security is implicitly covered, which is a common misconception. Security must be independently verified, not assumed from functional acceptance.
- ✗
Examine the project charter to confirm that security testing is listed as a deliverable in the overall project plan.
Why it's wrong here
While the project charter may mention security testing, it is a high-level document and does not ensure that security requirements are actually implemented in each sprint. The auditor needs to verify actual practice, not just plans. This option is insufficient because it focuses on documentation rather than evidence of security integration in the development process. It does not provide assurance that security controls are built into the system.
- ✓
Review the user stories and acceptance criteria to verify that security requirements are included and tested in each sprint.
Why this is correct
In Agile development, security requirements must be integrated into the product backlog as user stories or acceptance criteria to be addressed during sprints. By reviewing these, the auditor can confirm that security is continuously validated, not deferred to the end. This approach aligns with the principle of building security in from the start, ensuring that each increment meets security expectations. The other options either postpone security testing or focus on documentation rather than actual implementation.
- ✗
Recommend that a comprehensive security assessment be conducted only after the final sprint, just before deployment.
Why it's wrong here
Conducting security assessment only at the end contradicts Agile principles and increases the risk of costly rework. Vulnerabilities found late may be difficult to remediate and could delay deployment. Security should be addressed iteratively throughout the project. This option fails because it defers critical security validation, potentially allowing insecure code to accumulate and requiring significant rework, which is exactly what the auditor should prevent.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.