Certified Information Systems Auditor (CISA) — Question 183
During a post-implementation review, which of the following provides the BEST evidence that user requirements have been met?
Answer options
- A. Operator error logs
- B. End-user documentation
- C. User acceptance testing (UAT)
- D. Management interviews
Correct answer: C
Explanation
User acceptance testing (UAT) is specifically designed to determine if the system meets the specified user requirements, making it the most reliable evidence of satisfaction. In contrast, operator error logs may indicate issues but do not directly assess user needs, while end-user documentation and management interviews do not provide concrete evidence of user acceptance.