CRISC · Question #357
Which of the following should be of MOST concern to a risk practitioner reviewing the system development life cycle (SDLC)?
The correct answer is D. Testing is completed by IT support users without input from end users.. The absence of end-user involvement in testing during the SDLC is a significant concern for a risk practitioner, as it increases the risk of deploying a system that fails to meet actual business needs or contains undetected usability and functional defects.
Question
Which of the following should be of MOST concern to a risk practitioner reviewing the system development life cycle (SDLC)?
Options
- ATesting is completed in phases, with user testing scheduled as the final phase.
- BSegregation of duties controls are overridden during user testing phases.
- CData anonymization is used during all cycles of end-user testing.
- DTesting is completed by IT support users without input from end users.
How the community answered
(31 responses)- A13% (4)
- B6% (2)
- C3% (1)
- D77% (24)
Why each option
The absence of end-user involvement in testing during the SDLC is a significant concern for a risk practitioner, as it increases the risk of deploying a system that fails to meet actual business needs or contains undetected usability and functional defects.
Phased testing with user testing as a final phase is a common and acceptable SDLC practice, allowing for incremental validation.
Temporarily overriding segregation of duties controls during specific, controlled user testing phases might be necessary for practical testing purposes, provided proper oversight and logging are in place, and is less of a concern than lack of user input itself.
Data anonymization in end-user testing is a good practice for privacy and data protection, reducing risk rather than being a concern.
If testing is solely performed by IT support users without input from end users, there is a high risk that the system will not meet the actual business requirements, contain functional errors, or have usability issues, leading to operational inefficiencies and potential security vulnerabilities that could have been identified by those who use the system daily.
Concept tested: SDLC testing best practices
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/plan/testing-and-validation
Topics
Community Discussion
No community discussion yet for this question.