is-acquisition9 min read

Requirements Gathering and Management

Explore best practices for requirements gathering and management from an IS audit perspective, essential for CISA exam success.

CISAPractice|

Requirements gathering and management is one of the most critical activities in the system development lifecycle. Poor requirements are a leading cause of project failure, making this a key area for IS auditors and CISA candidates to understand.

Types of Requirements

  • Business Requirements: High-level objectives describing what the organization wants to achieve. These should align with the approved business case.
  • Functional Requirements: Specific behaviors and functions the system must perform, often documented as use cases or user stories.
  • Non-Functional Requirements: Quality attributes such as performance, availability, scalability, security, and usability.
  • Technical Requirements: Constraints related to technology platform, integration, data migration, and infrastructure.
  • Regulatory Requirements: Compliance obligations that the system must satisfy, including data protection, industry regulations, and internal policies.

Requirements Gathering Techniques

Effective requirements gathering uses multiple techniques to ensure completeness:

Interviews and Workshops

Structured interviews with stakeholders and facilitated workshops help capture business needs. These sessions should include representatives from all affected areas, not just the primary user group.

Document Analysis

Reviewing existing system documentation, process flows, and reports helps identify current capabilities and gaps.

Prototyping

Creating mockups or prototypes allows stakeholders to visualize the proposed system and provide feedback before development begins. This reduces the risk of misunderstood requirements.

Requirements Management

Once gathered, requirements must be managed throughout the project lifecycle:

Traceability

A requirements traceability matrix (RTM) maps each requirement to its source, design element, test case, and implementation status. This ensures that all requirements are addressed and tested.

Change Control

Requirements changes should follow a formal process that includes impact analysis, cost estimation, and stakeholder approval. Uncontrolled changes (scope creep) are a major project risk.

Prioritization

Requirements should be prioritized based on business value and risk. Techniques like MoSCoW (Must have, Should have, Could have, Won't have) help manage expectations and guide development sequencing.

Audit Considerations

IS auditors should assess:

  • Whether requirements are documented, complete, and traceable to business objectives
  • Whether stakeholders formally approved the requirements baseline
  • Whether a change control process exists for requirements modifications
  • Whether non-functional and security requirements are explicitly captured
  • Whether the requirements traceability matrix is maintained and current

CISA Exam Tips

Exam questions frequently test the auditor's ability to identify missing or inadequate requirements processes. Common scenarios include projects that proceeded without formal requirements sign-off, systems that lack security requirements, or organizations that have no process for managing requirements changes. Understanding these weaknesses and their potential impact is essential for exam success.

Related Tags

IS AcquisitionRequirements ManagementSDLCCISA Exam

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free