CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An organization is implementing a new payroll system using an agile methodology. Which TWO of the following are the MOST important controls for the IS auditor to assess?
⚠ Common exam trap
CISA often tests whether candidates recognize that agile replaces heavyweight documentation and CCB gates with backlog prioritization and sprint reviews — those who default to waterfall controls pick A, B, or C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The product backlog is prioritized and includes security requirements
Option D is correct because in agile development the product backlog is the authoritative, prioritized list of work items, and the IS auditor must verify that security requirements (e.g., access controls, encryption, audit logging for payroll data) are explicitly captured and prioritized there rather than deferred, since payroll systems handle sensitive PII and financial data. Option E is correct because sprint reviews are the key agile ceremony where stakeholders inspect the working increment and provide feedback, giving the auditor evidence of governance, stakeholder accountability, and that delivered functionality meets requirements. Option A is not the most important control in agile, where working software and lightweight documentation are favored over comprehensive design documentation. Option B is not the most important control because a formal change control board is characteristic of waterfall governance, whereas agile relies on backlog refinement and sprint-level change management. Option C is not the most important control because agile deliberately avoids a detailed upfront project plan with all tasks defined in advance, favoring iterative planning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Comprehensive documentation of all design decisions
Why it's wrong here
Agile favours working software over exhaustive documentation, so comprehensive records of every design decision are not a primary control. It tempts because documentation supports audit trails and change traceability, but for payroll the auditor prioritises authorisation, segregation of duties and input validation over design-decision records.
- ✗
A formal change control board to approve all changes
Why it's wrong here
Agile teams approve changes through backlog refinement and sprint reviews, so a change control board gating every change contradicts the iterative cadence the scenario requires. It is tempting because a CCB is the standard control for waterfall releases, where scheduled, batched approvals genuinely fit.
- ✗
A detailed project plan with all tasks upfront
Why it's wrong here
Agile plans emerge and are re-prioritised each sprint, so a fully detailed upfront task plan cannot reflect the payroll system's evolving requirements. It is tempting because comprehensive upfront planning is the correct control for waterfall projects, where scope is fixed before build begins.
- ✓
The product backlog is prioritized and includes security requirements
Why this is correct
A prioritised product backlog containing security requirements ensures controls are scheduled and delivered within sprints rather than deferred indefinitely. This satisfies the agile payroll scenario by embedding security into iterative planning, giving the auditor evidence that compliance and data protection needs are tracked alongside functional features.
- ✓
Sprint reviews are conducted with stakeholders to demonstrate working software
Why this is correct
Sprint reviews demonstrate working software to stakeholders, providing tangible evidence that controls and functionality are actually implemented each iteration. This satisfies the agile payroll scenario by giving the auditor verifiable artefacts and stakeholder confirmation, rather than relying solely on documentation produced before development.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.