A system development methodology is the structured way an organization turns requirements into working software. Auditors do not need to prefer one method, but they must understand where controls sit in each, what evidence to expect and what risks each method brings. The CISA exam frequently presents an agile or DevOps team and asks what the auditor should look for, so you need to recognize controls even when they look different from traditional sign-off documents.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.