← All Cheat Sheets

SDLC Phases Quick Reference

Every phase, its deliverables, and what the auditor checks.

SDLC Phases Quick Reference

The Software Development Life Cycle (SDLC) is tested across multiple CISA domains. Know each phase, its key deliverables, and what the IS auditor should verify.

Phase Key Deliverables Auditor Checks
1. Feasibility StudyBusiness case, cost-benefit analysis, feasibility reportVerify business justification and alignment with strategy
2. RequirementsFunctional and non-functional requirements, SRSConfirm user involvement and sign-off; check completeness
3. DesignSystem architecture, database design, interface specsReview security controls designed into the system
4. DevelopmentSource code, unit test results, code review recordsVerify coding standards, version control, separation of duties
5. TestingTest plans, test cases, defect reports, UAT sign-offConfirm independent testing; validate test coverage
6. ImplementationDeployment plan, training materials, data migration recordsVerify rollback plan, change management approval
7. MaintenanceChange requests, patch records, post-implementation reviewAudit change management process and emergency changes
8. DisposalData migration/destruction records, decommission planVerify secure data destruction and license termination

Testing Types to Know

Test Type Description
Unit TestingTests individual modules or functions in isolation
Integration TestingTests interactions between modules
System TestingTests the complete integrated system against requirements
UATUser acceptance testing; business users validate functionality
Regression TestingConfirms changes did not break existing functionality
Sociability TestingVerifies the new system works with existing systems

CISA Exam Tip

The auditor should be involved from the earliest phase (feasibility), not just at testing or implementation. Early involvement does not compromise independence as long as the auditor does not make management decisions.

Ready to test your knowledge?

Put this cheat sheet to work with scenario-based CISA practice questions.

Start Free