CISA · Question #407
An IS auditor discovers that an organization lacks a formal requirements validation process before software development starts. Which of the following is the PRIMARY risk associated with this deficien
The correct answer is B. Increased likelihood of scope creep, leading to project delays and cost overruns. Without a formal requirements validation process, requirements are often incomplete, ambiguous, or not agreed upon before development begins. This creates conditions for scope creep-stakeholders request additional features or changes mid-project because their actual needs were ne
Question
An IS auditor discovers that an organization lacks a formal requirements validation process before software development starts. Which of the following is the PRIMARY risk associated with this deficiency?
Options
- ACompromised quality control efforts, resulting in more defects in the final product
- BIncreased likelihood of scope creep, leading to project delays and cost overruns
- CDifficulty of effective resource allocation by project managers, impacting availability of staff
- DReduced communications between developers and stakeholders, resulting in slower adoption
How the community answered
(33 responses)- B91% (30)
- C3% (1)
- D6% (2)
Explanation
Without a formal requirements validation process, requirements are often incomplete, ambiguous, or not agreed upon before development begins. This creates conditions for scope creep-stakeholders request additional features or changes mid-project because their actual needs were never properly captured and validated upfront. Scope creep directly causes project delays and cost overruns. While quality defects (A) and communication issues (D) are real concerns, they are secondary effects. Resource allocation difficulties (C) are an indirect consequence. Scope creep is the most immediate and measurable risk of skipping requirements validation.
Topics
Community Discussion
No community discussion yet for this question.