Study sets
English

Certified Information Systems Auditor (CISA) | Domain 3 Acquisition and Development Governance 01

1 / 60.0s

Problem 1 ・ Question 1 / 6

Before a plan for a new system is approved, what should the IS auditor attach the most weight to?

View explanation

An investment decision evaluates the contribution to enterprise strategy, the expected value, the total cost and the main risks.

Problem 1 ・ Question 2 / 6

Why does the participation of the user departments matter most in defining requirements?

View explanation

Involving the users who understand the business makes the necessary functions, controls and priorities clear.

Problem 1 ・ Question 3 / 6

Which mechanism manages changes to a project's scope properly?

View explanation

Changes are approved and recorded formally after their effect on cost, schedule, quality and risk has been assessed.

Problem 1 ・ Question 4 / 6

When auditing agile development, what best shows progress and value?

View explanation

Agile confirms valuable output that meets the definition of done and the acceptance criteria in short iterations.

Problem 1 ・ Question 5 / 6

Which best describes the idea of security by design?

View explanation

The earlier in the life cycle control requirements are built in, the more effective and the cheaper they tend to be.

Problem 1 ・ Question 6 / 6

What is the main purpose of using an RFP when selecting packaged software?

View explanation

Setting out common functional, control and service requirements allows candidate proposals to be evaluated consistently.