Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An organization is implementing a new customer relationship management (CRM) system using an agile methodology. Which THREE areas should the IS auditor focus on to assess the effectiveness of controls during the development process?

⚠ Common exam trap

CISA often tests the misconception that agile projects should still follow waterfall-style documentation and plan adherence — candidates who pick A or E apply traditional audit thinking to an agile context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inclusion of security requirements in user stories

Option B is correct because in agile development, security requirements must be embedded into user stories and the product backlog so that controls are designed and tested iteratively rather than bolted on at the end; an IS auditor should verify that security acceptance criteria exist for each story. Option C is correct because sprint retrospectives are the agile mechanism for inspecting the process and identifying control and quality improvements, so their consistent conduct demonstrates an effective feedback loop for the development process. Option D is correct because code reviews and static analysis (e.g., SAST tools) provide technical verification of secure coding and defect detection at each increment, which is a key control compensating for the reduced reliance on phase-gate documentation in agile. Option A is not the best focus because formal change request documentation for every change reflects a traditional waterfall change-control model, whereas agile relies on backlog refinement and continuous integration rather than per-change formal requests. Option E is not appropriate because adherence to an original detailed project plan contradicts agile's adaptive, iterative planning, where scope and plans evolve across sprints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use of formal change request documentation for each change

    Why it's wrong here

    Agile teams manage change through a continuously refined backlog rather than formal change request documentation per change, so this control area does not fit the methodology. It tempts because formal change requests are standard in waterfall audits, where baselined scope makes documented approval essential.

  • ✓

    Inclusion of security requirements in user stories

    Why this is correct

    Embedding security requirements in user stories makes them estimable, testable and traceable within sprints. The auditor examines whether stories carry explicit security acceptance criteria, since this determines whether controls are actually built rather than deferred to post-release remediation.

  • ✓

    Conduct of sprint retrospectives to identify improvements

    Why this is correct

    Sprint retrospectives provide recurring evidence that the team inspects its process and acts on identified weaknesses. The auditor reviews retrospective records and resulting actions to confirm continuous improvement of development controls, rather than relying solely on end-of-project assurance.

  • ✓

    Performance of code reviews and static analysis

    Why this is correct

    Code reviews and static analysis directly address agile's compressed sprint cycles, where peer inspection and automated scanning catch defects before deployment. This satisfies the stem's requirement to assess controls during development, providing continuous assurance over code quality and security rather than relying on post-implementation testing alone.

  • ✗

    Adherence to the original detailed project plan

    Why it's wrong here

    Agile development deliberately abandons a fixed detailed plan, so adherence to one cannot measure control effectiveness; auditors instead examine iterative artefacts and sprint reviews. It tempts because plan-versus-actual variance is a valid audit technique under waterfall, where a baseline plan genuinely governs delivery.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.