SDLC Models: Waterfall, Agile and DevOps for Auditors
The model decides what evidence exists. Here's what each one leaves for the auditor.
An SDLC model is the shape a development project takes: one long sequence, a series of small releases, or a loop of prototypes. The phases are the same in all of them. What changes is how often they repeat and how much gets written down along the way.
For an auditor the model matters because it decides what evidence exists. A waterfall project leaves signed documents at every gate. An agile team leaves a backlog, sprint reviews and working software, with much of the knowledge in people's heads. Module 3 expects you to know each model's strengths and weaknesses, and to adjust the audit to match.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
The Models at a Glance
Waterfall
How it works
Phases run in strict sequence; each ends with formal review and sign-off
Best fit
Stable, well-defined requirements; less experienced teams
Main audit concern
Problems surface late, at system testing; changes after sign-off are costly and discouraged
Incremental
How it works
A series of mini-waterfalls, each delivering a working part of the system
Best fit
Large systems that can go live in parts
Main audit concern
Interfaces between increments; architecture built before all requirements are known
Prototyping
How it works
A working model is shown to users and refined before real development
Best fit
Users who cannot state requirements up front
Main audit concern
Users mistake the prototype for the finished system; controls left out of the model
Spiral
How it works
Iterations built around risk analysis, combining prototyping and waterfall
Best fit
Large, high-risk, shifting projects
Main audit concern
Needs a skilled project manager; cycles can run without firm deadlines
Rapid application development (RAD)
How it works
Time-boxed delivery with heavy user involvement and tools; scope shrinks before the deadline moves
Best fit
Business-focused systems needed quickly
Main audit concern
Quality, feature creep, inconsistent standards and documentation
Agile
How it works
Short time-boxed iterations (sprints), re-planned after each; small co-located teams
Best fit
Requirements that will change during the project
Main audit concern
Thin documentation, reliance on tacit knowledge, effort hard to estimate at the start
DevOps / DevSecOps
How it works
Development and operations integrated, with automation; DevSecOps builds security in end to end
Best fit
Frequent releases of web and mobile services
Main audit concern
Segregation of duties between those who write code and those who deploy it
| Model | How it works | Best fit | Main audit concern |
|---|---|---|---|
| Waterfall | Phases run in strict sequence; each ends with formal review and sign-off | Stable, well-defined requirements; less experienced teams | Problems surface late, at system testing; changes after sign-off are costly and discouraged |
| Incremental | A series of mini-waterfalls, each delivering a working part of the system | Large systems that can go live in parts | Interfaces between increments; architecture built before all requirements are known |
| Prototyping | A working model is shown to users and refined before real development | Users who cannot state requirements up front | Users mistake the prototype for the finished system; controls left out of the model |
| Spiral | Iterations built around risk analysis, combining prototyping and waterfall | Large, high-risk, shifting projects | Needs a skilled project manager; cycles can run without firm deadlines |
| Rapid application development (RAD) | Time-boxed delivery with heavy user involvement and tools; scope shrinks before the deadline moves | Business-focused systems needed quickly | Quality, feature creep, inconsistent standards and documentation |
| Agile | Short time-boxed iterations (sprints), re-planned after each; small co-located teams | Requirements that will change during the project | Thin documentation, reliance on tacit knowledge, effort hard to estimate at the start |
| DevOps / DevSecOps | Development and operations integrated, with automation; DevSecOps builds security in end to end | Frequent releases of web and mobile services | Segregation of duties between those who write code and those who deploy it |
Agile Is Not Uncontrolled
A common mistake is to treat agile as an excuse for missing controls. The controls move. Instead of a signed requirements document, look for an approved and prioritised backlog. Instead of one UAT sign-off, look for acceptance at each sprint review and a controlled release to production. A bank that ships its mobile app every two weeks while its core banking system follows a slower, formal change board runs two models at once, and the auditor tests each on its own terms.
DevOps raises the sharpest issue. When the same pipeline builds, tests and deploys code, the old rule that developers never touch production has to be enforced by automation and logging instead of by separate teams. Module 3 says plainly that the IS auditor should make sure proper separation of duties still exists.
Controls the Material Lists for a DevOps Approach
- checkAutomated software scanning and automated vulnerability scanning
- checkWeb application firewall
- checkSecurity training for developers
- checkSoftware dependency management
- checkAccess and activity logging
- checkDocumented policies and procedures
- checkApplication performance management
- checkAsset management and inventory
- checkContinuous auditing or monitoring
- checkEncryption of data passed between applications and services
Quick practice on audit concepts. No signup.
How the DISA Assessment Test Tests This
Most questions describe a project situation and ask which model fits, or which risk matters most in a given model.
- check_circleUsers cannot define requirements clearly: prototyping
- check_circleLarge, expensive, risk-driven project: spiral
- check_circleDeadline fixed, scope reduced to fit the time box: RAD
- check_circleRequirements expected to change, short iterations, small team: agile
- check_circleGreatest audit concern in DevOps: segregation of duties between development and production
- check_circleThe trap: picking the model with the most attractive strengths instead of the one whose description matches the scenario
FAQs
What is the difference between waterfall and agile for an auditor?expand_more
Waterfall gives formal sign-offs at the end of each phase, so evidence is documentary. Agile spreads acceptance across sprints and relies more on working software and team knowledge, so the auditor looks at backlog approval, sprint acceptance and release controls instead.
Which SDLC model is best when user requirements are unclear?expand_more
Prototyping. Users react to a working model and requirements firm up before real development starts.
What is DevSecOps?expand_more
DevOps with security built in from end to end: development, information security and operations working together, with automated security checks in the delivery pipeline.
What is the main risk of DevOps from an IS audit view?expand_more
Loss of segregation of duties, because the same team and pipeline can change and deploy code. Automated controls and logging have to replace separate teams.
Next steps
Take a full DISA mock testAssessment Test format, timed and scored.
