CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 472


Which of the following should be of GREATEST concern to an IS auditor reviewing a system software development project based on agile practices?

Show Answer
Correct Answer: D

The greatest concern for an IS auditor reviewing a system software development project based on agile practices should be the lack of secure coding practices. Ensuring secure coding is essential to protect the software from vulnerabilities and potential security breaches. In Agile methodologies, where rapid iterations and continuous integration are common, neglecting secure coding practices can lead to significant security risks. Security should always be a priority to safeguard the integrity and confidentiality of the system.

Discussion

4 comments
Sign in to comment
saado9Option: D
Mar 11, 2023

D. Lack of secure coding practices

AlyOption: A
May 21, 2023

A: Agile means "the ability to move quickly and easily". In the Agile method, programmers do not spend much time on documentation.

ChaBum
Mar 9, 2024

where did you learn Agile?

SibsankarOption: D
Mar 15, 2024

Secure coding practices are crucial for any software development project, regardless of methodology. In the fast-paced environment of agile development, the risk of vulnerabilities being introduced due to a lack of secure coding practices is heightened. Auditors should prioritize ensuring secure coding practices are implemented to minimize security risks in the final product. The answer is D

SwallowsOption: D
Jun 9, 2024

While lack of user acceptance testing (UAT) sign off (option B) is also a concern as it indicates potential gaps in validating the software against user requirements, the absence of secure coding practices poses a more immediate and severe risk to the security and integrity of the software and the organization's overall security posture. Therefore, it should be of greatest concern to an IS auditor reviewing a system software development project based on agile practices.