🇺🇸 Certified Information Systems Auditor (CISA) · flashcards

Certified Information Systems Auditor (CISA) Information Systems Acquisition, Development, and Implementation Flashcards

71 question-and-answer cards covering Information Systems Acquisition, Development, and Implementation as it is examined in Certified Information Systems Auditor (CISA). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

71Cards in deck
24Free preview
21Syllabus topics
~201Chars per answer
FreePrice

24 sample cards from the Information Systems Acquisition, Development, and Implementation deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What is configuration management (CM) and what is a configuration item?

    CM is the process of identifying, controlling, and tracking versions of system components (configuration items) and their relationships, ensuring a known, consistent, and auditable baseline of the system.

  2. Why is version control essential in software development?

    It tracks all changes to source code, supports concurrent work, enables rollback to prior versions, provides an audit trail of who changed what and when, and prevents unauthorized or lost changes.

  3. What is the role of Quality Assurance (QA) versus Quality Control (QC) in development?

    QA is process-oriented and preventive—ensuring development processes/standards are followed to prevent defects. QC is product-oriented and detective—testing/inspecting deliverables to find defects.

  4. What is a code review (peer review) and what control benefit does it provide?

    Systematic examination of source code by developers other than the author to find defects, security flaws, and standards violations early; it also enforces segregation of duties and reduces single-person risk.

  5. Why should test data and production data be kept separate, and what control applies to using production data in testing?

    To protect data integrity and confidentiality. If production data is used for testing, it should be sanitized/masked (de-identified) to protect sensitive information and comply with privacy requirements.

  6. Why must the test environment be separate from the production environment?

    To prevent testing activities from corrupting live data or disrupting operations, to enforce segregation of duties between development/testing and production, and to allow controlled, repeatable testing.

  7. What is go-live (deployment) readiness assessment?

    A pre-implementation check confirming that testing is complete and signed off, data is migrated, users are trained, fallback/rollback plans exist, support is ready, and required approvals are obtained before moving to production.

  8. Compare the parallel and direct (big-bang) changeover (cutover) strategies.

    Parallel runs old and new systems simultaneously until the new is proven (safe but costly/resource-intensive). Direct/big-bang switches off the old and on the new at once (cheap/fast but highest risk—no fallback).

  9. What is a phased changeover approach?

    Implementing the new system in stages (by module, location, or function) rather than all at once, which limits risk to a portion of the system but lengthens the transition and requires interim interfaces.

  10. What is a pilot changeover strategy?

    Deploying the new system to one site or user group first to validate it under real conditions before rolling it out organization-wide, limiting exposure if problems occur.

  11. What controls ensure data integrity during data migration/conversion?

    Record counts and control totals, hash/checksum reconciliation, field-by-field validation, before-and-after balancing, exception reporting, and sign-off that source and target data match completely and accurately.

  12. Why is reconciliation a key control in data conversion?

    To verify that all records were converted completely and accurately—comparing record counts and control/value totals between the legacy source and the new target so no data is lost, duplicated, or altered.

  13. What is the purpose of a post-implementation review (PIR)?

    Conducted after the system has stabilized to assess whether the project met its objectives, delivered expected benefits/ROI, and to capture lessons learned for future projects.

  14. When should a post-implementation review typically be conducted?

    After the system has been in production long enough to stabilize and demonstrate real benefits (commonly a few months post go-live), but soon enough that lessons learned and benefit data remain accurate.

  15. What is system acceptance and sign-off, and who should provide it?

    Formal confirmation that the delivered system meets agreed requirements and acceptance criteria. It should be approved by the system owner/business users (and sponsor), based on successful UAT, before final go-live.

  16. What are acceptance criteria in the context of system acceptance testing?

    Predefined, measurable conditions that the system must satisfy for users to accept it; they form the objective basis for UAT and the sign-off decision.

  17. What is the IS auditor's main concern when reviewing UAT results before go-live?

    That UAT was performed by appropriate end users, covered all critical requirements, that defects were resolved or formally accepted, and that documented sign-off exists before the system moves to production.

  18. What is a fallback (rollback/back-out) plan in deployment?

    A predefined procedure to restore the previous system/state if the new implementation fails, ensuring business continuity; its existence is a key go-live readiness control.

  19. What is scope creep and how is it controlled?

    Uncontrolled expansion of project scope without corresponding adjustments to time, cost, and resources. It is controlled through formal change/scope management, baselined requirements, and a requirements traceability matrix.

  20. What is a Work Breakdown Structure (WBS)?

    A hierarchical decomposition of the total project work into smaller, manageable deliverables and work packages, used as the basis for estimating, scheduling, assigning, and controlling work.

  21. What is function point analysis used for?

    A method to estimate software size and effort based on the functionality delivered to the user (inputs, outputs, inquiries, files, interfaces), independent of the technology or programming language used.

  22. What is the key risk of inadequate user involvement during requirements definition?

    The delivered system may not meet actual business needs, leading to rework, low adoption, scope changes, and benefit shortfalls—making early and continuous user participation a critical success factor.

  23. What is a quality gate (stage gate) in a project lifecycle?

    A predefined decision point between phases where deliverables and criteria are reviewed and formally approved before the project is allowed to proceed, enforcing control and accountability.

  24. What risk does emergency change handling pose, and what compensating control applies?

    Emergency changes may bypass normal approval/testing, risking instability or unauthorized changes. Compensating control: documented emergency procedures with after-the-fact review, approval, and full logging/reconciliation of what was changed.

What this deck covers

The Information Systems Acquisition, Development, and Implementation deck follows the Certified Information Systems Auditor (CISA) Information Systems Acquisition, Development, and Implementation syllabus — 5 chapters and 21 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 14.2 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 201 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Information Systems Acquisition, Development, and Implementation flashcards FAQ

How many Information Systems Acquisition, Development, and Implementation flashcards are in this Certified Information Systems Auditor (CISA) deck?

71 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Certified Information Systems Auditor (CISA) flashcards free?

Yes. The preview here is free to read with no signup, and the full 71-card deck is free inside the Examius app.

What do the Information Systems Acquisition, Development, and Implementation cards cover?

They follow the Certified Information Systems Auditor (CISA) Information Systems Acquisition, Development, and Implementation syllabus — 5 chapters and 21 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.