Inspirational journeys

Follow the stories of academics and their research expeditions

CISA—Certified Information Systems Auditor - Part 215

Mary Smith

Wed, 15 Apr 2026

CISA—Certified Information Systems Auditor - Part 215

1. Which of the following is the PRIMARY objective of an IT performance measurement process?

A) Minimize errors
B) Gather performance data
C) Establish performance baselines
D) Optimize performance



2. When auditing the proposed acquisition of a new computer system, an IS auditor should FIRST establish that:

A) a clear business case has been approved by management.
B) corporate security standards will be met.
C) users will be involved in the implementation plan.
D) the new system will meet all required user functionality.



3. Documentation of a business case used in an IT development project should be retained until:

A) the end of the system's life cycle.
B) the project is approved.
C) user acceptance of the system.
D) the system is in production.



4. Which of the following risks could result from inadequate software baselining?

A) Scope creep
B) Sign-off delays
C) Software integrity violations
D) inadequate controls



5. The most common reason for the failure of information systems to meet the needs of users is that:

A) user needs are constantly changing.
B) the growth of user requirements was forecast inaccurately.
C) the hardware system limits the number of concurrent users.
D) user participation in defining the system's requirements was inadequate.



1. Right Answer: D
Explanation: An IT performance measurement process can be used to optimize performance, measure and manage products/services, assure accountability and make budget decisions. Minimizing errors is an aspect of performance, but not the primary objective of performance management. Gathering performance data is a phase of IT measurement process and would be used to evaluate the performance against previously established performance baselines.

2. Right Answer: A
Explanation: The first concern of an IS auditor should be to establish that the proposal meets the needs of the business, and this should be established by a clear business case. Although compliance with security standards is essential, as is meeting the needs of the users and having users involved in the implementation process, it is too early in the procurement process for these to be an IS auditor's first concern.

3. Right Answer: A
Explanation: A business case can and should be used throughout the life cycle of the product. It serves as an anchor for new (management) personnel, helps to maintain focus and provides valuable information on estimates vs. actuals. Questions like, ' why do we do that', ' What was the original intent' and ' how did we perform against the plan' can be answered, and lessons for developing future business cases can be learned. During the development phase of a project one should always validate the business case, as it is a good management instrument. After finishing a project and entering production, the business case and all the completed research are valuable sources of information that should be kept for further reference

4. Right Answer: A
Explanation: A software baseline is the cut-off point in the design and development of a system beyond which additional requirements or modifications to the design do not or cannot occur without undergoing formal strict procedures for approval based on a business cost-benefit analysis. Failure to adequately manage the requirements of a system through baselining can result in a number of risks. Foremost among these risks is scope creep, the process through which requirements change during development. Choices, C and D may not always result, but choice A is inevitable.

5. Right Answer: D
Explanation: Lack of adequate user involvement, especially in the system's requirements phase, will usually result in a system that does not fully or adequately address the needs of the user. Only users can define what their needs are, and therefore what the system should accomplish.

0 Comments

Leave a comment