← CISA: audit IT, controls, and resilience
04 / 8 · 30 MIN

Delivery, migration, and acceptance

Trace requirements and evidence to delivered artifacts and data.

Concept and mechanism

Project audit checks whether objectives, risks, and controls accompany acquisition, design, development, and implementation. An installed server is a deliverable; fewer settlement failures is a benefit requiring its own criteria and follow-up. In agile methods, evidence may reside in acceptance criteria, reviews, pipeline results, and release decisions. Do not impose another methodology’s documents unnecessarily or accept that sprints eliminate authorization and control. Traceability should connect requirement, test, artifact, and environment. Testing artifact A does not automatically demonstrate B’s behavior, even if the hotfix has few lines.

Guided application

During migration, combine counts, identifiers, value controls, and relevant conversion rules. Two databases with 12,000 rows may have differing EUR totals; equal counts do not prove monetary integrity. Investigate by currency and transformation rule without adjusting values to hide discrepancies. Assess rollback as recovery of consistent state across code, schema, and data. Retaining the old binary does not resolve an incompatible transformation. Audit communicates gaps and consequences to decision authority without executing changes or accepting risk for management. After go-live, compare results against the business case and distinguish timely delivery from realized benefits.

IN PRACTICE

The plan returns to the previous application version but cannot read the new schema: code rollback is insufficient.

Common pitfalls

Counts as total integrity; signature as functional testing; sprint as waiver of criteria; go-live as benefit.

Related topics: Audit operations, batches, and interfaces · Resilience and recovery evidence

Take this idea with you

Connect acceptance to the actual state entering production.

Create account

Reference: Assessing Security and Privacy Controls · CISA outline effective August 1, 2024