CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An organization is implementing an agile methodology for a new software project. Which of the following is the MOST effective control to ensure that security requirements are addressed?
⚠ Common exam trap
CISA often tests the misconception that security can be handled in a separate phase or at the end; candidates may incorrectly choose a single review or final audit instead of continuous backlog integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Including security requirements in the product backlog
In agile methodologies, security requirements must be treated as first-class backlog items so they are prioritized, estimated, and delivered iteratively alongside functional requirements. Including them in the product backlog ensures continuous visibility and integration into each sprint, rather than being an afterthought. This approach aligns with the principle of building security in from the start and adapting to evolving threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conducting a single security requirements review at the start of the project
Why it's wrong here
One upfront requirements review cannot address security that emerges as the backlog evolves across sprints, so later stories may ship without controls. It is tempting because early requirements definition suits plan-driven projects, yet agile needs security criteria refined continuously in each iteration's definition of done.
- ✓
Including security requirements in the product backlog
Why this is correct
Placing security requirements in the product backlog makes them backlog items the team estimates, prioritises and completes each sprint, so they are continuously addressed rather than bolted on. This satisfies agile's iterative delivery while ensuring security is not deferred.
- ✗
Requiring a separate security sprint after development
Why it's wrong here
Deferring security to a separate sprint after development means flaws are found once code is written, so remediation costs rise and security is not built into each increment. It is tempting because a dedicated sprint appears to guarantee security attention, yet continuous backlog-embedded security work is what agile requires.
- ✗
Performing a security audit only at the end of the project
Why it's wrong here
A single end-of-project audit detects security gaps only after all increments are complete, leaving no opportunity to correct them within iterations. It is tempting because audits provide formal assurance and suit waterfall phases, but agile demands security verification embedded in every sprint rather than one terminal checkpoint.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.