ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessMedium

An IS auditor is performing an audit of the software development lifecycle (SDLC) process. The organization uses an agile development methodology. The auditor observes that user stories are frequently changed during sprints, and formal sign-offs for requirements are often skipped to maintain development speed. What is the PRIMARY audit concern in this scenario?

  1. AIncreased risk of scope creep and project delays.
  2. BPotential for reduced user satisfaction due to uncontrolled changes.
  3. CDifficulty in tracing requirements back to delivered functionality.
  4. DNon-compliance with traditional waterfall SDLC documentation standards.
Show answer & explanation

Correct answer: C. Difficulty in tracing requirements back to delivered functionality.

While agile methods embrace change, the lack of formal sign-offs and frequent, undocumented changes make it difficult for the auditor to trace whether the final product truly meets the original or evolved business requirements. This traceability is crucial for ensuring the system's integrity and fitness for purpose.

Why the other options are wrong

  • A. Agile is designed to manage scope creep, and while delays can occur, the primary concern is the lack of control over requirements.
  • B. User satisfaction is a business outcome; the audit concern is about the control over the development process that leads to that outcome.
  • D. Agile does not adhere to traditional waterfall documentation standards, so this is not a valid audit concern in an agile environment.

Requirements Traceability

The ability to track and link requirements throughout the entire software development lifecycle, from inception to deployment and testing.

  • Ensures all requirements are met.
  • Facilitates impact analysis of changes.
  • Crucial for quality assurance and auditability.

Memory trick: Agile changes are fine, but if you can't 'trace the breadcrumbs', you're lost.

More Domain 1: Information System Auditing Process questions