ExamGecko
Question list
Search
Search

Related questions

Question 20 - CISA discussion

Report
Export

Which of the following would be an IS auditor's GREATEST concern when reviewing the early stages of a software development project?

A.
The lack of technical documentation to support the program code
Answers
A.
The lack of technical documentation to support the program code
B.
The lack of completion of all requirements at the end of each sprint
Answers
B.
The lack of completion of all requirements at the end of each sprint
C.
The lack of acceptance criteria behind user requirements.
Answers
C.
The lack of acceptance criteria behind user requirements.
D.
The lack of a detailed unit and system test plan
Answers
D.
The lack of a detailed unit and system test plan
Suggested answer: C

Explanation:

User requirements are statements that describe what the users expect from the software system in terms of functionality, quality, and usability. They are essential inputs for the software development process, as they guide the design, implementation, testing, and deployment of the system. Therefore, an IS auditor's greatest concern when reviewing the early stages of a software development project would be the lack of acceptance criteria behind user requirements. Acceptance criteria are measurable conditions that define when a user requirement is met or satisfied. They help ensure that the user requirements are clear, complete, consistent, testable, and verifiable. Without acceptance criteria, it would be difficult to evaluate whether the system meets the user expectations and delivers value to the organization. Technical documentation, such as program code, is usually produced in later stages of the software development process. Completion of all requirements at the end of each sprint is not mandatory in agile software development methods, as long as there is a prioritized backlog of requirements that can be delivered incrementally. A detailed unit and system test plan is also important for ensuring software quality, but it depends on well-defined user requirements and acceptance criteria.Reference:Information Systems Acquisition, Development & Implementation,CISA Review Manual (Digital Version)

asked 18/09/2024
Chaston Williams
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first