Home > Glossary > Certified Information Systems Auditor > Software Development Life Cycle (SDLC)

📖 What is Software Development Life Cycle (SDLC)?

Software Development Life Cycle (SDLC) is a structured process used by the IT industry to design, develop, and test high-quality software. It consists of several phases, including requirements gathering, design, coding, testing, deployment, and ongoing maintenance.

🥋 Sensei Says:

"Student, be prepared to identify which phase a specific activity belongs to. For example, creating a functional specification happens during the requirements/design phase."

📚 Certification: Certified Information Systems Auditor (CISA)

🔑 What are the Key Concepts of Software Development Life Cycle (SDLC)?

  • Requirements Traceability Matrix (RTM) ensures every business requirement is mapped to a design element, a line of code, and a specific test case.
  • Segregation of Duties (SoD) is critical, requiring that developers do not have access to migrate code into the production environment to prevent unauthorized changes.
  • User Acceptance Testing (UAT) is the final validation phase where end-users confirm the system meets business needs before formal sign-off and deployment.
  • The transition from SDLC to Change Management occurs during deployment, ensuring all promoted code is documented, approved, and can be rolled back if necessary.
  • Audit evidence for SDLC includes signed-off requirement documents, test plans, bug logs, and formal approval records for each phase gate transition.

🎯 How does Software Development Life Cycle (SDLC) appear on the CISA Exam?

A scenario might describe a system failure immediately after deployment; you may be asked to identify which SDLC phase was likely bypassed or poorly executed, such as UAT.

You may be asked to identify the most significant risk when a small development team shares administrative access across development, testing, and production environments.

Expect questions where you must determine the best method to verify that all requested business functionalities were actually implemented and tested in the final software release.

❓ Frequently Asked Questions

What is the primary difference between System Integration Testing (SIT) and User Acceptance Testing (UAT)?

SIT focuses on the technical interfaces and data flow between different software modules or systems. UAT focuses on whether the software fulfills the business requirements and is acceptable to the end-user.


Why should an auditor be particularly concerned with the maintenance phase of the SDLC?

Maintenance often involves emergency patches or 'hotfixes' that may bypass formal SDLC controls. Auditors check for retrospective approvals to ensure these changes didn't introduce security vulnerabilities or undocumented features.

Related Terms from Certified Information Systems Auditor

📝 Related Study Guides

Deep Dive 10 min read

CISA Exam: What to Expect and How to Prepare in 2026

The CISA exam consists of 150 multiple-choice questions to be completed in 4 hours, requiring a scaled score of 450/800 to pass. Preparation requires mastering five domains focusing on IT auditing, governance, acquisition, operations, and asset protection. Success depends on a risk-based mindset and understanding frameworks like COBIT.

Deep Dive 10 min read

Mastering COBIT 2019 for the CISA Exam

COBIT 2019 is a comprehensive framework for the governance and management of enterprise IT. For CISA candidates, it provides the essential structure to evaluate how an organization aligns IT goals with business objectives, manages risk, and ensures value delivery through a clear distinction between governance and management activities.

Comparison 7 min read

Attribute vs. Variable Sampling: CISA Exam Guide

Attribute sampling is used for compliance testing to determine if a control is functioning (yes/no), while variable sampling is used for substantive testing to estimate a numerical value or monetary amount. For the CISA exam, remember that attribute sampling checks for existence, and variable sampling checks for value.

🧠

Test Your Knowledge

Think you understand Software Development Life Cycle (SDLC)? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium