Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An IS auditor is reviewing the requirements definition phase of a new system development project. The business analyst has documented functional requirements but has not yet defined non-functional requirements. Which of the following is the MOST significant risk of proceeding to the design phase without non-functional requirements?

⚠ Common exam trap

The trap here is focusing on project management symptoms like timeline or budget overruns, rather than the core risk of delivering a system that does not meet quality attributes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The system may not meet performance, security, and availability expectations.

Non-functional requirements specify criteria such as performance, security, and availability that are essential for system acceptance. Proceeding without them increases the likelihood that the system will fail to meet stakeholder expectations and may require costly rework. The auditor should verify that both functional and non-functional requirements are defined and approved before design begins.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The system may not meet performance, security, and availability expectations.

    Why this is correct

    Non-functional requirements define quality attributes such as performance, security, and availability. Without them, designers may make assumptions that lead to a system that fails to meet stakeholder expectations. These attributes are often costly to retrofit later. The auditor should ensure non-functional requirements are defined and approved before design begins to mitigate this risk.

  • ✗

    The development team may not understand the business processes.

    Why it's wrong here

    Functional requirements typically cover business processes. The gap here is non-functional requirements, which are about system qualities. While misunderstanding business processes is a risk, it is not directly caused by missing non-functional requirements. The auditor should focus on the specific risk of unmet quality attributes.

  • ✗

    The project timeline may be extended due to rework.

    Why it's wrong here

    While rework is a possible consequence, it is a secondary effect. The primary risk is that the system will not satisfy critical quality attributes. Timeline extension is a project management concern, but the more significant risk is delivering a system that is unusable or insecure, which could have broader business impact.

  • ✗

    The project budget may be exceeded.

    Why it's wrong here

    Budget overrun is a potential outcome, but it is not the most significant risk. The absence of non-functional requirements can lead to a system that fails to meet legal, regulatory, or business continuity needs. Budget issues are important but secondary to the risk of a system that cannot support the business.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.