Certified Information Systems Auditor (CISA) — Question 265
During the evaluation of controls over a major application development project, the MOST effective use of an IS auditor's time would be to review and evaluate:
Answer options
- A. cost-benefit analysis.
- B. acceptance testing.
- C. application test cases.
- D. project plans.
Correct answer: D
Explanation
Reviewing the project plans allows the IS auditor to understand the overall structure and objectives of the project, ensuring that controls are aligned with project goals. The other options, while important, focus on specific aspects of the project that may not provide a comprehensive view of control effectiveness.