D3IS Acquisition & Development

IS Acquisition & Development: Exam Tips

SDLC Phases Must Include Security Controls

Security requirements should be defined during the requirements gathering phase, not added later. Each SDLC phase should have defined deliverables, review checkpoints, and approval gates before proceeding to the next phase.

Feasibility Studies Justify Project Investment

A feasibility study evaluates technical, economic, operational, and schedule viability before committing resources. The business case should include a cost-benefit analysis with metrics such as return on investment (ROI), net present value (NPV), and internal rate of return (IRR).

Project Governance Ensures Stakeholder Oversight

A project steering committee provides executive oversight and resolves escalated issues. The IS auditor should verify that project governance includes defined roles, decision rights, escalation procedures, and regular status reporting to stakeholders.

Understand All Levels of Software Testing

Unit testing validates individual components; integration testing verifies interactions between modules; system testing evaluates the complete solution; and user acceptance testing (UAT) confirms the system meets business requirements. Each level serves a distinct purpose.

Change Management Protects Production Integrity

All changes to production systems should follow a formal change management process that includes request, impact analysis, approval, testing, and rollback planning. Emergency changes must still be documented and reviewed after implementation.

Configuration Management Tracks System Baselines

Configuration management ensures that only authorized and documented changes are made to system components. A configuration management database (CMDB) maintains records of all configuration items and their relationships.

Post-Implementation Review Measures Success

A post-implementation review should occur after system stabilization to compare actual outcomes against projected benefits. It evaluates whether the project met its objectives, stayed within budget, and identifies lessons learned for future projects.

Agile Methods Require Adapted Audit Approaches

Agile development uses iterative sprints with continuous delivery, which changes traditional audit checkpoints. The IS auditor should verify that security, documentation, and control requirements are embedded within the agile process rather than deferred.

Separation of Duties in Development Environments

Developers should not have access to promote code to production or modify production data. Separate development, testing, staging, and production environments prevent unauthorized changes and reduce the risk of untested code reaching production.

Acquisition Contracts Must Define Control Requirements

When acquiring software or services, contracts should specify security requirements, data ownership, audit rights, and service level agreements. The right-to-audit clause allows the organization to verify the vendor's compliance with contractual obligations.