CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An IS auditor is reviewing the requirements definition phase of a new system development project. The auditor finds that business users have provided functional requirements, but non-functional requirements are largely missing. Which TWO of the following are the MOST significant risks of proceeding without well-defined non-functional requirements? (Choose two.)
⚠ Common exam trap
The trap here is focusing on functional gaps or project management issues, while overlooking that non-functional requirements encompass security and performance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The system may lack necessary security controls.
Non-functional requirements cover critical aspects such as performance, scalability, security, and availability. Omitting them increases the risk that the system will fail to meet operational expectations and security needs. These failures can lead to system outages, data breaches, and user rejection, making them the most significant risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The development team may not understand the business processes.
Why it's wrong here
Business processes are usually captured in functional requirements. The scenario states that functional requirements are provided, so the team likely has some understanding. The gap is in non-functional aspects, not in business process understanding. Thus, this is not a primary risk arising from the missing non-functional requirements.
- ✗
The project may exceed its budget due to scope creep.
Why it's wrong here
Scope creep is typically associated with changes in functional requirements or additional features. While missing non-functional requirements can lead to rework and cost overruns, the direct risk is not scope creep but rather system inadequacy. The scenario focuses on the absence of non-functional requirements, not on uncontrolled changes. Therefore, this is not the most significant risk.
- ✓
The system may lack necessary security controls.
Why this is correct
Security requirements, including authentication, authorization, encryption, and auditing, are often classified as non-functional. If they are not specified, developers may not implement them, leaving the system vulnerable to breaches. This is a critical risk because security is essential for protecting data and complying with regulations. Thus, this is a major consequence of missing non-functional requirements.
- ✗
The system may be difficult to maintain due to lack of documentation.
Why it's wrong here
Documentation quality is a separate concern from non-functional requirements. While non-functional requirements can include maintainability, the absence of documentation is not a direct consequence of missing them. Documentation practices are typically governed by development standards. Therefore, this is not the most significant risk in this context.
- ✓
The system may not meet performance and scalability expectations.
Why this is correct
Non-functional requirements define criteria such as response time, throughput, and concurrent user capacity. Without them, the system may be designed without adequate infrastructure or optimization, leading to poor performance under load. This can result in user dissatisfaction, productivity loss, and costly rework. Therefore, this is a significant risk directly tied to the omission.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.