Which SDLC Quality Elements Must an IS Auditor Review?
An IS auditor is reviewing an organization’s system development life cycle (SDLC). Which of the following MUST be included in the review?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the distinction between developer implementation and auditor verification, highlighting the common trap of selecting utilization over validation.
This CISA question tests the core responsibility of an IS auditor reviewing the SDLC, establishing that validating adherence to quality standards is mandatory. The page clarifies why verification trumps mere utilization during an audit.
Option B is frequently selected because it describes a legitimate development activity, but auditors do not utilize standards; they assess compliance against them.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An IS auditor’s primary objective during an SDLC review is to provide independent assurance that controls function as intended. Option C correctly identifies validation as the mandatory audit activity because auditors must verify that development teams actually follow established quality frameworks like ISO 9001 or CMMI. Without explicit validation, the organization cannot confirm that software defects are minimized or that deliverables meet business requirements.Why the Other Options Are Wrong
Option A focuses on ownership, which is a governance and management responsibility rather than a direct audit testing procedure. Option B describes how developers should work, but the auditor’s role is to evaluate whether those standards were applied, not to apply them. Option D belongs to the project planning phase where stakeholders define success criteria, making it irrelevant to the retrospective audit review process.Community Comment Notes
Learners consistently recognize validation as the core audit function, with several noting that reviewers must ensure processes follow established quality benchmarks. One candidate noted they were "torn between B and C", seeking evidence to differentiate them. The distinction lies in role separation: developers implement and utilize standards, while auditors independently validate adherence. As multiple users confirmed, confirming compliance at each lifecycle stage remains the definitive audit requirement.Exam Strategy
When answering SDLC audit questions, always distinguish between what the development team executes versus what the auditor verifies. Look for keywords like validate, assess, or review to identify the auditor's actual responsibility and avoid confusing operational tasks with assurance activities.
Frequently Asked Questions
Why isn't utilizing standards the auditor's duty?
Developers utilize standards during coding; auditors independently verify compliance against them.
Does defining quality attributes belong in the SDLC audit?
No, defining attributes occurs during project initiation, not during the retrospective audit review.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →