CISA Domain 3 Study Guide: SDLC and Implementation
A comprehensive study guide covering SDLC and implementation topics in CISA Domain 3, Information Systems Acquisition, Development, and Implementation.
CISA Domain 3, Information Systems Acquisition, Development, and Implementation, covers the processes and controls for acquiring, developing, testing, and deploying information systems. This study guide consolidates the key topics you need to master for the exam.
SDLC Phases and Audit Objectives
The Systems Development Life Cycle (SDLC) provides a framework for managing IT projects from inception through retirement. Regardless of methodology (waterfall, agile, spiral), auditors must verify that appropriate controls exist at each phase.
Key SDLC Phases
- Feasibility Study: Evaluates technical, economic, and operational feasibility. The auditor verifies that a business case exists and alternatives were considered.
- Requirements Definition: Documents functional and nonfunctional requirements. The auditor checks that requirements are traceable and approved by stakeholders.
- Design: Translates requirements into system architecture and detailed specifications. The auditor reviews design documentation for completeness and security considerations.
- Development: Code is written and unit tested. The auditor evaluates coding standards, code review processes, and version control practices.
- Testing: System, integration, user acceptance, and regression testing. The auditor verifies test coverage, defect management, and sign-off procedures.
- Implementation: The system is deployed to production. The auditor reviews deployment procedures, rollback plans, and post-implementation reviews.
Critical Concepts for Domain 3
- Change Management: All changes to production systems should follow a formal change management process with request, review, approval, testing, and documentation.
- Configuration Management: Tracking and controlling changes to software and hardware configurations throughout the lifecycle.
- Program Library Management: Controls over source code libraries, including access restrictions, version control, and promotion procedures.
- Data Conversion and Migration: Controls that ensure data integrity during system transitions, including validation, reconciliation, and rollback capabilities.
Acquisition Considerations
When organizations acquire software rather than building it, auditors should evaluate the vendor selection process, contract terms (including SLAs, escrow agreements, and exit clauses), and the due diligence performed on the vendor's security and financial stability.
Study Strategy for Domain 3
Domain 3 typically represents about 12% of the CISA exam. Focus your study on understanding the purpose of each SDLC phase, the controls that should exist at each phase, and the auditor's role in evaluating project governance. Practice questions that present scenarios and ask you to identify the most significant risk or the most appropriate control.
Review the concepts of function point analysis, use case modeling, and software quality metrics, as these topics appear in exam questions related to project estimation and quality assurance.