In this episode of the CISA Study Series, we explore the foundations of Information Systems Acquisition and Development and examine how organizations plan, acquire, design, develop, secure, and control information systems throughout the system development lifecycle.
These slides covers the key concepts, controls, methodologies, and audit considerations that every IS auditor should understand when evaluating system development projects. From project governance and feasibility studies to software development methodologies, DevOps, DevSecOps, software acquisition, configuration management, infrastructure development, control design, and data validation controls, this module provides a practical overview of how systems are built and governed.