🇺🇸 Certified Information Systems Auditor (CISA) · subject
Certified Information Systems Auditor (CISA) Information Systems Acquisition, Development, and Implementation Syllabus
Every chapter and topic of Information Systems Acquisition, Development, and Implementation examined in Certified Information Systems Auditor (CISA) — 5 chapters, 21 topics and 10 sub-topics, plus 71 flashcards written against it.
Information Systems Acquisition, Development, and Implementation syllabus — full chapter and topic list
Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Information Systems Acquisition, Development, and Implementation in Certified Information Systems Auditor (CISA), not a summary of it.
-
Project Governance and Management
5 topics- Project portfolio and program management
- Business case and benefits realization
- Project management methodologies
- Waterfall, Agile, and hybrid approaches
- Project roles, governance structures, and oversight
- Project risk, scheduling, and resource management
- The auditor's role across the project lifecycle
- Project portfolio and program management
-
Business Case and Feasibility
4 topics- Feasibility study and requirements definition
- Cost-benefit and ROI analysis
- Build vs. buy and acquisition decisions
- RFP process and vendor evaluation
- Requirements traceability
-
System Development Methodologies
4 topics- Systems development life cycle (SDLC) phases
- Agile, Scrum, and DevOps practices
- CI/CD pipelines and automated testing
- Prototyping, RAD, and reuse approaches
- Application controls design
- Input, processing, and output controls
- Data integrity and validation controls
-
Testing, Configuration, and Quality Assurance
4 topics- Testing strategies and levels
- Unit, integration, system, and UAT
- Regression, performance, and security testing
- Configuration and change management in development
- Quality assurance and code review practices
- Test environment and data management
- Testing strategies and levels
-
System Implementation and Migration
4 topics- Deployment and go-live readiness
- Conversion strategies: parallel, phased, pilot, big bang
- Data migration and conversion controls
- Post-implementation review
- Benefits realization validation and lessons learned
- System acceptance and sign-off
- Deployment and go-live readiness
Information Systems Acquisition, Development, and Implementation flashcards for Certified Information Systems Auditor (CISA)
25 of 71 cards from the Information Systems Acquisition, Development, and Implementation deck — real questions with worked answers.
What is a project portfolio in IT project management?
A collection of projects and programs grouped together to enable effective management and prioritization of investments to meet strategic business objectives. Selection is typically based on alignment, risk, and expected return.
How does a 'program' differ from a 'project'?
A project is a temporary endeavor with a defined start and end that produces a unique product or result. A program is a group of related projects managed in a coordinated way to obtain benefits not available from managing them individually.
What is the primary purpose of project portfolio management (PPM)?
To select, prioritize, and balance the organization's mix of projects/programs to maximize value and strategic alignment within resource and risk constraints, rather than to manage execution of any single project.
Name three common project management methodologies an IS auditor should recognize.
Waterfall (traditional/predictive), Agile (iterative/adaptive, e.g., Scrum), and PRINCE2 (structured, process-based). PMBOK is a knowledge framework rather than a strict methodology.
In a project governance structure, what is the role of the project steering committee?
A senior management body that provides overall direction, approves the business case and major decisions, allocates funding, resolves cross-functional conflicts, and oversees that the project meets business objectives.
What is the role of the project sponsor?
The senior executive who owns the business case, secures funding and resources, champions the project, and is ultimately accountable for realizing the project's business benefits.
What does the critical path of a project represent?
The longest sequence of dependent activities through the project network, which determines the shortest possible project duration. Any delay on a critical-path activity delays the whole project.
Define 'slack' (float) in project scheduling.
The amount of time an activity can be delayed without delaying the project end date (total float) or the early start of the next activity (free float). Critical-path activities have zero total float.
What scheduling technique uses optimistic, most likely, and pessimistic estimates?
PERT (Program Evaluation and Review Technique). Expected time = (Optimistic + 4 x Most likely + Pessimistic) / 6, accounting for uncertainty in estimates.
In Earned Value Management, how is Schedule Variance (SV) calculated and what does a negative value mean?
SV = EV - PV (Earned Value minus Planned Value). A negative SV means the project is behind schedule; positive means ahead.
In Earned Value Management, how is Cost Variance (CV) calculated?
CV = EV - AC (Earned Value minus Actual Cost). A negative CV indicates a cost overrun; positive indicates under budget.
What is a Gantt chart used for in project management?
A bar chart that displays project activities against a calendar timeline, showing start/finish dates, durations, overlaps, and progress. Good for scheduling/status but does not clearly show dependencies like a network diagram.
What is the IS auditor's appropriate role during a system development project?
To provide independent, advisory review of controls, risks, and adherence to methodology at each phase WITHOUT making management decisions or designing controls, to preserve auditor independence and objectivity.
Why should an IS auditor be involved early in the SDLC rather than only after implementation?
Because controls are far cheaper and easier to build in during design than to retrofit afterward, and early involvement lets the auditor identify control weaknesses before they become costly to fix.
What is the purpose of a feasibility study?
To evaluate whether a proposed system is technically, economically, operationally, and legally viable, and to recommend the best alternative before significant resources are committed.
List the common dimensions of feasibility evaluated in a feasibility study.
Technical, economic (cost-benefit), operational, schedule, and legal/regulatory feasibility. Some frameworks add the TELOS or PESTLE dimensions.
What characterizes good (well-defined) system requirements?
They are complete, consistent, unambiguous, testable/verifiable, traceable, feasible, and prioritized, and they reflect actual user/business needs.
What is requirements traceability and why does it matter?
The ability to link each requirement forward to design, code, and test cases (and back to its source), ensuring every requirement is built and tested and no unauthorized functionality is added (scope creep).
What tool documents requirements traceability?
A Requirements Traceability Matrix (RTM), which maps each requirement to its design element, code component, and test case to verify coverage.
What is the formula for Return on Investment (ROI)?
ROI = (Net Benefit / Cost) x 100, where Net Benefit = Total Benefits - Total Costs. It expresses the gain relative to the investment as a percentage.
What is Net Present Value (NPV) and what decision rule applies?
NPV is the sum of discounted future cash flows minus the initial investment. Accept the project if NPV > 0 (it adds value); reject if NPV < 0.
What is the payback period in a cost-benefit analysis?
The length of time required for the cumulative net cash inflows of a project to recover the initial investment. Shorter payback is generally preferred but it ignores time value of money and post-payback returns.
What is Total Cost of Ownership (TCO) and why is it used in acquisition decisions?
The full lifecycle cost of a system including acquisition, implementation, training, operation, maintenance, and disposal. It gives a more realistic basis than purchase price alone for build-vs-buy comparisons.
In a build-vs-buy decision, what favors buying (acquiring) a commercial off-the-shelf package?
Faster implementation, lower upfront risk/cost, vendor-supported maintenance and upgrades, and proven functionality—best when requirements are common and not a competitive differentiator.
In a build-vs-buy decision, what favors building (in-house development)?
Unique/competitive-advantage requirements, the need for full control and customization, no suitable package exists, and integration or security needs that packages cannot meet.
See more Information Systems Acquisition, Development, and Implementation flashcards →
Planning Information Systems Acquisition, Development, and Implementation for Certified Information Systems Auditor (CISA)
Information Systems Acquisition, Development, and Implementation is about 18% of the Certified Information Systems Auditor (CISA) syllabus by topic count — 21 of 119 topics, spread over 5 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 20 hours.
The heaviest chapters are Project Governance and Management (5 topics), Business Case and Feasibility (4 topics), System Development Methodologies (4 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.
Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.
Information Systems Acquisition, Development, and Implementation (Certified Information Systems Auditor (CISA)) FAQ
What is in the Certified Information Systems Auditor (CISA) Information Systems Acquisition, Development, and Implementation syllabus?
Information Systems Acquisition, Development, and Implementation is split into 5 chapters — Project Governance and Management, Business Case and Feasibility, System Development Methodologies, Testing, Configuration, and Quality Assurance and System Implementation and Migration, containing 21 topics and 10 sub-topics in total.
How is Information Systems Acquisition, Development, and Implementation structured in the Certified Information Systems Auditor (CISA) syllabus?
5 chapters. Information Systems Acquisition, Development, and Implementation accounts for about 18% of the topics in the whole Certified Information Systems Auditor (CISA) syllabus (21 of 119).
How long should I spend on Information Systems Acquisition, Development, and Implementation for Certified Information Systems Auditor (CISA)?
Budget around 20 hours for a first pass through Information Systems Acquisition, Development, and Implementation — about 45 minutes per topic plus 12 minutes per sub-topic across its 21 topics. Add revision cycles on top.
Are there flashcards for Certified Information Systems Auditor (CISA) Information Systems Acquisition, Development, and Implementation?
Yes — a 71-card Information Systems Acquisition, Development, and Implementation deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.