Available now
Domain 3: IS Acquisition, Development and Implementation
Project governance and the controls that decide whether a new system arrives trustworthy. The smallest domain.
12%
of the exam
7
lessons
21
exam questions
56
minutes
Start here
Project Governance, the Business Case and Feasibility
- 1Project Governance, the Business Case and FeasibilityBefore a line of code is written, who owns the project, what justifies it, and what the auditor may and may not do. The exam tests the sponsor's ownership and the auditor's independence.8 min · 3 questions · video
- 2The SDLC and Designing Controls InControls are cheapest, and strongest, when they are specified at requirements, not bolted on after go-live. The exam tests where in the life cycle control belongs, and why requirements decide a project's fate.8 min · 3 questions · video
- 3Development Methodologies: Waterfall, Agile and the AuditorWaterfall gives neat control checkpoints; agile moves faster but the evidence looks different. The exam tests that agile does not mean uncontrolled, and that the control objectives never change.8 min · 3 questions · video
- 4Testing: From Unit to User AcceptanceTesting proves a system meets its requirements, and acceptance belongs to the users, not the developers. The exam tests who signs off, and why live data has no place in a test environment.8 min · 3 questions · video
- 5Data Conversion and MigrationMoving data to a new system is a one-time, high-risk event. The exam tests reconciliation of source to target, and why the auditor verifies the counts rather than trusting a 'migration complete' report.8 min · 3 questions · video
- 6Implementation Strategies and the Post-Implementation ReviewParallel, phased or direct: the changeover you choose is a risk decision, and the project is not finished until a review confirms the benefits. The exam tests the fallback, and what a PIR is actually for.8 min · 3 questions · video
- 7Application Controls: Input, Processing and OutputThe controls that make a system's transactions complete, accurate and valid, and how they differ from the general controls beneath them. The exam tests which category a control belongs to, and why input validation alone is not enough.8 min · 3 questions · video
Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Domain structure reflects the published exam content outline and is not reproduced from ISACA materials.
Stay ahead of cyber threats
Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.
No spam. Unsubscribe at any time.
