CISA Domain 3 Study Guide 2026: IS Acquisition & Development
Master the processes for acquiring, developing, and implementing information systems to ensure they meet your organization's strategic objectives.
Quick answer: This study guide organizes all our resources for CISA Domain 3: Information Systems Acquisition, Development, and Implementation. Explore in-depth articles on project management, SDLC, Agile, DevOps, and vendor evaluation to prepare for this section of the CISA exam.
Key facts
- Question count:
- Approximately 18 questions (12% of 150 total)
- Weight of exam:
- 12%
- Focus areas:
- SDLC, Project Management, Agile, DevOps, Vendor Evaluation
- Total exam time:
- 4 hours (240 minutes)
Overview
Domain 3 is where practitioners often stumble, not because the concepts are foreign, but because they are too familiar. Your hands-on experience as a developer, project manager, or systems administrator is a huge asset, but it can become a liability on exam day. The CISA exam will punish you for thinking like a builder; it demands you think like an auditor.
What Makes This Domain Deceptively Difficult
The single biggest trap in Domain 3 is answering questions from the perspective of the person doing the work. The exam doesn't care about the most efficient way to code a feature or the fastest way to close a project. It cares about assurance, risk, and control. You will be presented with scenarios where your real-world impulse might be to fix a problem directly. You must resist this and instead adopt the auditor's mindset, which is always one step removed: evaluate the process, identify the control weakness, and assess the business risk.
This domain covers a wide waterfront of methodologies, from traditional Waterfall SDLC to Agile, DevOps, and third-party software acquisition. You can't just know the textbook definitions. The exam will test your ability to apply audit principles to each context. For example, a question won't ask you to list the phases of the SDLC. It will ask you to identify the greatest risk during the requirements gathering phase of a new financial application, or to determine the most important control for an emergency change to a production system. These are judgment calls, and the correct answer always aligns with the priorities of an IS auditor: protecting the organization and ensuring objectives are met.
Where to Focus Your First 10 Hours
At 12% of the exam, this domain requires focused, efficient study. Don't try to boil the ocean by memorizing every project management framework. Instead, spend your first 10 hours mastering the core concepts from an auditor's point of view.
| Priority | Topic Area | Key Questions to Answer |
|---|---|---|
| 1 | The Auditor's Role in the SDLC | What is the auditor's primary objective at each phase (from feasibility to post-implementation)? What evidence should you look for to confirm controls are working? |
| 2 | Project Governance & Management | How do you audit a project's business case for validity? What are the key control points in a project lifecycle (e.g., go/no-go decisions)? How do you assess if project risks are being managed effectively? |
| 3 | Testing Controls & UAT | What is the difference between unit, integration, system, and acceptance testing from an assurance perspective? What is the auditor's role in User Acceptance Testing (UAT)? |
| 4 | Change & Configuration Management | What controls are essential for ensuring changes are authorized, tested, and implemented properly? How do you audit emergency changes? |
Mastering these four areas first builds the foundation you need for everything else. The principles of auditing a Waterfall project's change control board are the same principles you'll adapt when evaluating a DevOps CI/CD pipeline; the context changes, but the control objectives (authorization, testing, segregation of duties) remain.
The Mindset Shift That Prevents Simple Mistakes
Many candidates hemorrhage points by choosing answers that are technically correct but not the best answer from an auditor's perspective. Your job is not to solve the problem; it's to evaluate the framework that allowed the problem to occur.
Before you answer any question in this domain, take a breath and perform this mental check:
- Am I thinking like a manager or an auditor? A manager wants to meet a deadline. An auditor wants to ensure the process is controlled and repeatable, even if it takes longer.
- Does my answer address a symptom or a root cause? Fixing a single bug is addressing a symptom. Evaluating why the quality assurance process failed to catch the bug is addressing the root cause. The CISA exam almost always prefers the root cause answer.
- Is this about technical implementation or business risk? While technical details matter, the CISA is a business-focused certification. Always connect the technical issue back to its potential impact on the organization's objectives, data integrity, or compliance posture. The answer with the clearest link to business risk is often the correct one.
If you can consistently apply this three-point check, you will avoid the simple mistakes that come from relying on your practitioner instincts. You'll be evaluating the scenarios not as a participant, but as the independent assurance professional the CISA certification expects you to be.
Every guide in this cluster (5)
Every published article that belongs to this cluster, organized by type. New content is added continuously.