Which SDLC Quality Elements Must an IS Auditor Review?

SDLC Auditing & Quality Assurance
Answer Correct answer: C — Validate that system development processes adhere to quality standards during the SDLC review.

An IS auditor is reviewing an organization’s system development life cycle (SDLC). Which of the following MUST be included in the review?

  1. Ownership of the system quality management plan
  2. Utilization of standards in the system development processes and procedures
  3. Validation that system development processes adhere to quality standards Correct Answer
  4. Definition of quality attributes to be associated with the system

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the distinction between developer implementation and auditor verification, highlighting the common trap of selecting utilization over validation.

This CISA question tests the core responsibility of an IS auditor reviewing the SDLC, establishing that validating adherence to quality standards is mandatory. The page clarifies why verification trumps mere utilization during an audit.

Option B is frequently selected because it describes a legitimate development activity, but auditors do not utilize standards; they assess compliance against them.

Community Discussion (3 comments)

Cisagroup 👍 1 Selected: C
When reviewing an organization’s System Development Life Cycle (SDLC), an IS auditor must ensure that system development processes follow established quality standards (e.g., ISO 9001, CMMI, ITIL, COBIT)
46080f2 👍 1 Selected: C
An IS auditor reviewing an organization’s SDLC must validate that development processes adhere to established quality standards. This involves verifying compliance with documented procedures at each phase of the lifecycle, such as design specifications, testing protocols, and post-implementation controls12. For example, auditors assess whether design documents align with institutional standards, whether testing follows approved methodologies, and whether changes are properly authorized13. While utilization of standards (B) is important, the audit’s critical function is validation (C) to ensure actual adherence rather than mere existence of standards. Quality attributes (D) and ownership details (A) are context-dependent considerations rather than universal requirements for every SDLC review.
blehbleh 👍 1
I am torn between B and C. If someone can explain why one is correct with evidence that would be helpful.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

An IS auditor’s primary objective during an SDLC review is to provide independent assurance that controls function as intended. Option C correctly identifies validation as the mandatory audit activity because auditors must verify that development teams actually follow established quality frameworks like ISO 9001 or CMMI. Without explicit validation, the organization cannot confirm that software defects are minimized or that deliverables meet business requirements.

Why the Other Options Are Wrong

Option A focuses on ownership, which is a governance and management responsibility rather than a direct audit testing procedure. Option B describes how developers should work, but the auditor’s role is to evaluate whether those standards were applied, not to apply them. Option D belongs to the project planning phase where stakeholders define success criteria, making it irrelevant to the retrospective audit review process.

Community Comment Notes

Learners consistently recognize validation as the core audit function, with several noting that reviewers must ensure processes follow established quality benchmarks. One candidate noted they were "torn between B and C", seeking evidence to differentiate them. The distinction lies in role separation: developers implement and utilize standards, while auditors independently validate adherence. As multiple users confirmed, confirming compliance at each lifecycle stage remains the definitive audit requirement.

Exam Strategy

When answering SDLC audit questions, always distinguish between what the development team executes versus what the auditor verifies. Look for keywords like validate, assess, or review to identify the auditor's actual responsibility and avoid confusing operational tasks with assurance activities.

Frequently Asked Questions

Why isn't utilizing standards the auditor's duty?

Developers utilize standards during coding; auditors independently verify compliance against them.

Does defining quality attributes belong in the SDLC audit?

No, defining attributes occurs during project initiation, not during the retrospective audit review.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide