IT Acquisition, Development, and Implementation Flashcards
7 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 IT Acquisition, Development, and Implementation flashcards as text
When evaluating vendor proposals during system acquisition, what should an IS auditor verify is included in the RFP (Request for Proposal)?
Answer: Security, compliance, and audit requirements
Including security, compliance, and audit requirements in the RFP ensures vendors understand and commit to these critical obligations from the outset of the relationship.
What does 'parallel operation' mean in the context of a system cutover strategy?
Answer: Both the old and new systems run concurrently for a validation period
Parallel operation runs both the legacy and new system simultaneously so organizations can verify the new system produces correct results before fully decommissioning the old one.
A change advisory board (CAB) is PRIMARILY responsible for which activity?
Answer: Reviewing and authorizing change requests prior to implementation
The CAB reviews change requests and authorizes implementation, ensuring each change is evaluated for risk, business impact, and necessity before proceeding.
Which rollback procedure consideration is MOST critical before executing a production system upgrade?
Answer: Whether the rollback procedure has been tested and a documented fallback plan exists
Testing the rollback procedure before go-live ensures the organization can reliably revert to the prior stable state if the upgrade fails.
In IT governance and change management, the RACI model is used to define which of the following?
Answer: Responsible, Accountable, Consulted, and Informed roles
RACI stands for Responsible, Accountable, Consulted, and Informed — a framework that clearly defines roles and responsibilities for each activity in a process.
Formal change management for infrastructure changes exists PRIMARILY to achieve which outcome?
Answer: Prevent unauthorized changes and minimize the risk of unplanned outages
Formal change management requires authorization and testing before deployment, preventing unauthorized modifications and reducing the likelihood of outages caused by failed changes.
An IS auditor finds that emergency changes are implemented without any post-implementation review. This finding represents:
Answer: A control weakness that requires remediation
All changes, including emergency changes, require post-implementation review to confirm objectives were met and to assess any residual risks introduced.