| « Management Assessment of Internal Controls - Section 404 Sarbanes Oxley | SAP Interview Question - PGI Post Goods Issue » |
Certified Information Systems Auditor Exam - SDLC Systems Development Lifecycle Question
Certified Information Systems Auditor Exam - SDLC Systems Development Lifecycle Question
Here is a simple Question adapted from the CISA exam.
Q). In a Systems Development Lifecycle, information security controls should be
Options:
A. Designed during the implementation phase
B. Implemented Prior to Validation
C. Should be taken up as part of the feasibility stage
D. Specified after the coding phase
Answer: As a best practice controls should be taken up in the feasibility stage of the SDLC. The earlier the controls are introduced in the SDLC, the cheaper they are and the easier it is to ensure better controls.
1 comment
and Questions on the New 2006 CISA Content Areas.
Thanks !
miki
This post has 5 feedbacks awaiting moderation...