Information Systems Acquisition and Development
A CISA aspirant should have a sound understanding of information systems acquisition, development, and implementation processes. You should be able to understand how an organization evaluates, develops, implements, maintains, and disposes of its information systems and related components. By understanding these processes, you can identify the potential risks that might arise during the acquisition, development, or implementation of information systems. This allows better planning and risk reduction.
This chapter covers Domain 3, Information Systems Acquisition, Development and Implementation, part A, Information Systems Acquisition and Development.
The following topics will be covered in this chapter:
- Project management structure
- Business case and feasibility analysis
- System development methodologies
- Control identification and design
You will now explore each of these in detail.