← All Cheat Sheets
SDLC Phases Quick Reference
Every phase, its deliverables, and what the auditor checks.
SDLC Phases Quick Reference
The Software Development Life Cycle (SDLC) is tested across multiple CISA domains. Know each phase, its key deliverables, and what the IS auditor should verify.
| Phase | Key Deliverables | Auditor Checks |
|---|---|---|
| 1. Feasibility Study | Business case, cost-benefit analysis, feasibility report | Verify business justification and alignment with strategy |
| 2. Requirements | Functional and non-functional requirements, SRS | Confirm user involvement and sign-off; check completeness |
| 3. Design | System architecture, database design, interface specs | Review security controls designed into the system |
| 4. Development | Source code, unit test results, code review records | Verify coding standards, version control, separation of duties |
| 5. Testing | Test plans, test cases, defect reports, UAT sign-off | Confirm independent testing; validate test coverage |
| 6. Implementation | Deployment plan, training materials, data migration records | Verify rollback plan, change management approval |
| 7. Maintenance | Change requests, patch records, post-implementation review | Audit change management process and emergency changes |
| 8. Disposal | Data migration/destruction records, decommission plan | Verify secure data destruction and license termination |
Testing Types to Know
| Test Type | Description |
|---|---|
| Unit Testing | Tests individual modules or functions in isolation |
| Integration Testing | Tests interactions between modules |
| System Testing | Tests the complete integrated system against requirements |
| UAT | User acceptance testing; business users validate functionality |
| Regression Testing | Confirms changes did not break existing functionality |
| Sociability Testing | Verifies the new system works with existing systems |
CISA Exam Tip
The auditor should be involved from the earliest phase (feasibility), not just at testing or implementation. Early involvement does not compromise independence as long as the auditor does not make management decisions.
Ready to test your knowledge?
Put this cheat sheet to work with scenario-based CISA practice questions.
Start Free