Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

AI2.8 - Software Quality Assurance

This topic is intended to enable collaboration and sharing of information to facilitate a better understanding and approach to implementing this COBIT control objective based on the risk, value and guidance provided by its corresponding control practices.

COBIT Control Objective AI2.8 - Software Quality Assurance is contained within Process Popup Acquire and Maintain Application Software.

Learn more about COBIT and related publications.

Click “Join This Community” to be able to actively participate in discussions and contribute content. You must be an ISACA member to join this topic. Join ISACA now.

This Topic Has:
14 Members
0 Online
4347 Visits

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!

Badge: Energizer

Software Quality Assurance

Develop, resource and execute a software QA plan to obtain the quality specified in the requirements definition and the organisation’s quality policies and procedures.

View value and Risk Drivers  help

Hide value and Risk Drivers help

Value Drivers

  • All-embracing test approach
  • Performed tests reflecting the business processes and requirements
  • Formally accepted software
  Risk Drivers
  • Poor software quality
  • Retesting of developed software
  • Tests failing to reflect current business processes
  • Test data misused and compromising corporate security
  • Insufficient testing
  • Breach of compliance requirements

View Control Practices  help

Hide Control Practices  help

  1. Define a software QA plan. Ensure that the plan includes:
    • Specification of quality criteria
    • Validation and verification processes
    • Definition of how quality will be reviewed
    • Necessary qualifications of quality reviewers
    • Roles and responsibilities for the achievement of quality
    • The effect of embedding quality within the development process
    • The presence or absence of formal review by independent QA teams
    • Ensuring that reviewers are independent from the development team
  2. Design a process that monitors the software quality based on:
    • Project requirements
    • Enterprise policies
    • Adherence to site development systems methodologies
    • Quality management procedures and acceptance criteria
  3. Employ code inspection, programme walk-throughs and testing of applications. Report on outcomes of the monitoring process and testing to the application software development team and IT management.
  4. Monitor all quality exceptions. Ensure that corrective actions are taken. Maintain a record of all reviews, results, exceptions and corrections. Repeat quality reviews, where appropriate, based on the amount of rework and corrective action.

Discussions: 1 total

Must be a Topic member to contribute
Hi everyone, I consult for some small software development companies, most of who neither have Quality Assurance unit nor carry out tests on their software before shipping - they simply rely on the programmer's ingenuity to develop a fail-proof system. Th...
Abiola Ilupeju | 5/27/2016 5:33:12 AM | COMMENTS(0)

Documents & Publications: 67 total

Must be a Topic member to contribute
View All »
Posted by ISACA 1453 days ago
Posted by ISACA 532 days ago
Posted by ISACA 746 days ago
Posted by ISACA 851 days ago

Events & Online Learning: 12 total

Journal Articles: 233 total

Volume 3, 2107
by Jayakumar Sundaram, CISA, ISO 27001 LA
The SoA is a continuously updated and controlled document that provides an overview of information security implementation.
Volume 6, 2106
by Venkatasubramanian Ramakrishnan, CISM, CRISC, CHFI
Bayesian networks can capture the complex interdependencies among risk factors and can effectively combine data with expert judgment.
Volume 2, 2018
by Ofir Eitan, CISM, CCSK, CTI
In the wake of the Target breach, the threat of cyberattacks using an enterprise’s supply chain as a delivery vector has become a common concern within the information security community.
Volume 2, 2018
by Robert E. Davis, DBA, CISA, CICA
Innovation is the process of transforming an idea or concept into a functional and marketable value proposition reflecting creative opportunity.
Volume 2, 2018
Until a few years ago, many organizations did not adopt new technologies unless they were proven, stabilized and in use.
Volume 2, 2018
by Indrajit Atluri, CRISC, CISM, CISSP, HCISPP, ITILv3
Cyber insurance, along with cyberrisk, has become a very common agenda item on the boardroom discussion list in recent times.

Wikis: 2 total

Blog Posts: 146 total

La Tecnología de la Información (TI), en todas sus áreas (base de datos, seguridad de la información, desarrollo de software, redes, etc.), debe tener como objetivo primario el apoyo a los Procesos del Negocio (PN) de la organización. Sin embargo, es comú...
Posted By : emorro | 0 comments
Have you experienced ransomware attack so far and, if yes, what did you do to resolve? I set up Twitter poll here: It lasts for seven days. Thank you for taking part in the poll.
Posted By : Dragan Pleskonjic | 5 comments
Bitcoin Trade a Bubble! Block Chain Technology Useful .ISACA Members whats your Take on Bitcoin Trade, Is its a bubble that wont last long.Block chain Technology is useful and its continuously growing to as form of secure record  management and secured us...
Posted By : MUGAMBI865 | 1 comments
There is no doubt with our current business environment, we will be experiencing more cyber breaches in the next few months.  The latest threat is an architectural design flaw in newer CPU's.  These design vulnerabilities could allow attackers to intercep...
Posted By : Fred586 | 1 comments
There are some math models for business that MBAs are taught. Just like assembling burgers for fast food or call wait queue management in a call center, vulnerability patching is a time based business opportunity. Leadership can be expected to use this ...
Posted By : Don Turnblade | 1 comments
My personal thoughts after listening to C-level executives at the CxO Roundtable Series sponsored by Intel, IBM, HyTrust & ReedSmith. For an invite, please reach out to me. Data Protection under the GDPR For past few months, I’ve been helping to org...
Posted By : Thomas152 | 1 comments