An organization is implementing a new financial system using the waterfall SDLC model. Which of the following is the MOST critical control to ensure that business requirements are met?
Trap 1: Automated unit testing results
Unit tests verify that individual code units behave as the developers intended; they do not confirm the system satisfies documented business requirements. They would be the right control for validating code correctness during construction, whereas waterfall demands formal requirements traceability and user acceptance testing before sign-off.
Trap 2: Code reviews by the development team
Code reviews check implementation quality, style and defects among developers; they cannot confirm the system meets documented business requirements. They are the right control for improving code correctness during development, whereas waterfall requires formal requirements traceability and user acceptance testing before the system is accepted.
Trap 3: Detailed technical design documents
Technical design documents describe how the system will be built, not whether it delivers the agreed business requirements. They are the correct artefact for guiding developers during construction, but waterfall's requirements phase needs traceability and user acceptance testing to confirm business needs are actually met.
- A
Automated unit testing results
Why it fails: Unit tests verify that individual code units behave as the developers intended; they do not confirm the system satisfies documented business requirements. They would be the right control for validating code correctness during construction, whereas waterfall demands formal requirements traceability and user acceptance testing before sign-off.
- B
Code reviews by the development team
Why it fails: Code reviews check implementation quality, style and defects among developers; they cannot confirm the system meets documented business requirements. They are the right control for improving code correctness during development, whereas waterfall requires formal requirements traceability and user acceptance testing before the system is accepted.
- C
Detailed technical design documents
Why it fails: Technical design documents describe how the system will be built, not whether it delivers the agreed business requirements. They are the correct artefact for guiding developers during construction, but waterfall's requirements phase needs traceability and user acceptance testing to confirm business needs are actually met.
- D
Formal user acceptance testing (UAT) sign-off
Formal UAT sign-off requires business users to validate the system against documented requirements before go-live, providing the definitive control that confirms business requirements are met. This satisfies the waterfall model's need for verification at the testing phase before implementation proceeds.