CISA Practice Question: Information Systems Acquisition, Development, and Implementation
In a waterfall SDLC, which phase requires formal sign-off from the business owner before proceeding to the next phase?
⚠ Common exam trap
CISA often tests whether candidates know which waterfall phase requires business owner sign-off, trapping those who pick design or testing because those phases also involve approvals but not the formal scope-baselining gate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Requirements phase
In a waterfall SDLC, the requirements phase concludes with formal business owner sign-off because it establishes the baseline for all subsequent design, development, and testing work. Once requirements are approved, changes become costly and require change control, so the business owner must formally accept the documented requirements before the project proceeds. This sign-off ensures mutual agreement on scope and reduces the risk of rework downstream.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Development phase
Why it's wrong here
Development produces the solution from approved specifications; the business owner signs off earlier, on the requirements baseline, before design or coding starts. It is tempting because developers do hand work back for review, yet that review confirms technical build quality, not the business authorisation to proceed.
- ✓
Requirements phase
Why this is correct
Requirements are baselined and formally approved by the business owner before design begins, since later phases build directly on that frozen scope. Sign-off here authorises the project to proceed, whereas design and testing approvals occur within their own phases.
- ✗
Design phase
Why it's wrong here
The design phase produces specifications from approved requirements; business sign-off there is internal review, not the formal gate authorising the project to proceed. Formal business-owner approval belongs to the requirements phase, where the baseline is accepted. Design sign-off would be the correct answer only if the stem asked which phase validates technical specifications.
- ✗
Testing phase
Why it's wrong here
Testing verifies the built solution against requirements, so business sign-off there validates the finished product rather than authorising progression from requirements. It is tempting because testing does involve business users confirming acceptance, but that approval occurs after development, not as the gate before design begins.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.