Exam CISA All QuestionsBrowse all questions from this exam
Question 1261

At which stage of the system development life cycle (SDLC) is it MOST beneficial to perform a risk assessment?

    Correct Answer: A

    Performing a risk assessment prior to system development is most beneficial because it allows identification and mitigation of potential risks at the earliest possible stage. This proactive approach helps in planning for security, resource allocation, and other critical factors, thus setting a solid foundation for the entire development process.

Discussion
SwallowsOption: A

While conducting risk assessments at each stage of the life cycle (option B) is valuable to continuously monitor and manage risks throughout the project, addressing risks early (prior to system development) sets a strong foundation for effective risk management across all subsequent stages of the SDLC. Therefore, option A, performing a risk assessment prior to system development, is often considered the most beneficial stage in the SDLC to conduct a risk assessment.