Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An organization is implementing a new payroll system using an agile methodology. Which TWO of the following are the MOST important controls for the IS auditor to assess?

⚠ Common exam trap

CISA often tests whether candidates recognize that agile replaces heavyweight documentation and CCB gates with backlog prioritization and sprint reviews — those who default to waterfall controls pick A, B, or C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The product backlog is prioritized and includes security requirements

Option D is correct because in agile development the product backlog is the authoritative, prioritized list of work items, and the IS auditor must verify that security requirements (e.g., access controls, encryption, audit logging for payroll data) are explicitly captured and prioritized there rather than deferred, since payroll systems handle sensitive PII and financial data. Option E is correct because sprint reviews are the key agile ceremony where stakeholders inspect the working increment and provide feedback, giving the auditor evidence of governance, stakeholder accountability, and that delivered functionality meets requirements. Option A is not the most important control in agile, where working software and lightweight documentation are favored over comprehensive design documentation. Option B is not the most important control because a formal change control board is characteristic of waterfall governance, whereas agile relies on backlog refinement and sprint-level change management. Option C is not the most important control because agile deliberately avoids a detailed upfront project plan with all tasks defined in advance, favoring iterative planning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Comprehensive documentation of all design decisions

    Why it's wrong here

    Agile favours working software over exhaustive documentation, so comprehensive records of every design decision are not a primary control. It tempts because documentation supports audit trails and change traceability, but for payroll the auditor prioritises authorisation, segregation of duties and input validation over design-decision records.

  • ✗

    A formal change control board to approve all changes

    Why it's wrong here

    Agile teams approve changes through backlog refinement and sprint reviews, so a change control board gating every change contradicts the iterative cadence the scenario requires. It is tempting because a CCB is the standard control for waterfall releases, where scheduled, batched approvals genuinely fit.

  • ✗

    A detailed project plan with all tasks upfront

    Why it's wrong here

    Agile plans emerge and are re-prioritised each sprint, so a fully detailed upfront task plan cannot reflect the payroll system's evolving requirements. It is tempting because comprehensive upfront planning is the correct control for waterfall projects, where scope is fixed before build begins.

  • ✓

    The product backlog is prioritized and includes security requirements

    Why this is correct

    A prioritised product backlog containing security requirements ensures controls are scheduled and delivered within sprints rather than deferred indefinitely. This satisfies the agile payroll scenario by embedding security into iterative planning, giving the auditor evidence that compliance and data protection needs are tracked alongside functional features.

  • ✓

    Sprint reviews are conducted with stakeholders to demonstrate working software

    Why this is correct

    Sprint reviews demonstrate working software to stakeholders, providing tangible evidence that controls and functionality are actually implemented each iteration. This satisfies the agile payroll scenario by giving the auditor verifiable artefacts and stakeholder confirmation, rather than relying solely on documentation produced before development.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.