ISACA Certified Information Systems Auditor (CISA) Exam flashcards
185 free flashcards. Tap a card to flip it.
Net Present Value (NPV)
Flip cardNPV is a financial metric used to evaluate the profitability of a project or investment, taking into account the time value of money.
- Calculates the present value of future cash flows minus the initial investment.
- A positive NPV indicates a potentially profitable investment.
- Requires a discount rate to account for the opportunity cost of capital.
Memory trick: NPV says 'Now, Profit' for future money.
DRP Business Alignment
Flip cardThe principle that a Disaster Recovery Plan (DRP) must be fully integrated with and support the organization's overarching business continuity objectives, ensuring the recovery of all critical business functions, not just IT systems.
- Extends beyond IT to include processes, people, and facilities.
- Based on Business Impact Analysis (BIA) findings.
- Prioritizes recovery based on business criticality.
Memory trick: DRP Business: Recovery for the Whole Business Machine.
IT Governance Integration
Flip cardThe process of ensuring that IT strategies and objectives are aligned with the overall business strategies and objectives, and that IT resources are used effectively to achieve organizational goals.
- Ensures IT supports business objectives.
- Involves leadership and organizational structures.
- Critical for value delivery from IT investments.
Memory trick: IT governance is the 'glue' that links tech to business goals.
Actionable Security Policy
Flip cardAn actionable security policy is clearly written, defines key terms, specifies required behaviors, outlines responsibilities, and details consequences for non-compliance, enabling effective implementation and enforcement.
- Provides clear guidance to employees.
- Defines scope, responsibilities, and expectations.
- Essential for consistent security practices.
Memory trick: A blurry map leads to getting lost, not to the treasure of security.
Software Asset Management (SAM)
Flip cardThe practice of managing and optimizing the purchase, deployment, maintenance, utilization, and disposal of software applications within an organization to ensure compliance and cost-effectiveness.
- Prevents over-licensing (waste) and under-licensing (non-compliance).
- Requires continuous monitoring of installations and usage.
- Reduces legal and financial risks.
Memory trick: Untracked software, unexpected fines.
Continuous Requirements Validation
Flip cardAn ongoing process throughout the system development lifecycle to ensure that the evolving system design and implementation consistently align with current and anticipated business needs and stakeholder expectations.
- Crucial for dynamic projects.
- Prevents scope creep and rework.
- Ensures solution relevance to business goals.
Memory trick: Project's on track, but the map's outdated!
IT Governance Effectiveness
Flip cardThe degree to which an organization's IT governance framework successfully ensures that IT delivers value, manages risks, and aligns with business objectives.
- Requires active engagement from leadership.
- Involves clear roles and responsibilities.
- Measured by achievement of strategic goals.
Memory trick: Ignoring the steering committee means IT is driving blind, off the business road.
IT Governance Cultural Impact
Flip cardThe successful implementation of an IT governance framework significantly depends on its alignment with the organization's culture and the willingness of management and employees to adapt to new processes, roles, and reporting structures.
- Cultural resistance is a major barrier to change.
- New frameworks often require changes in behavior and mindset.
- Management buy-in and employee engagement are crucial.
Memory trick: You can lead a horse to water, but you can't make it think like a fish.
Cloud Exit Strategy
Flip cardA documented plan outlining the procedures, responsibilities, and technical requirements for migrating data and applications out of a cloud provider's environment.
- Ensures data ownership and access upon termination.
- Prevents vendor lock-in.
- Addresses data format, transfer methods, and timelines.
- Should be defined in the contract with the CSP.
Memory trick: Cloud Contract: Exit Strategy is Key.
Least Privilege Principle
Flip cardA security principle requiring that users and processes are granted only the minimum necessary authorizations to perform their functions, and no more.
- Minimizes potential damage from errors or malicious acts.
- Reduces attack surface.
- Requires regular access reviews.
Memory trick: Too many keys too soon means open doors for trouble.
Segregation of Duties (SoD)
Flip cardA control principle that divides critical functions among different individuals or teams to prevent any single person from having complete control over a process, thereby reducing the risk of error, fraud, or misuse.
- Prevents a single point of failure or compromise.
- Enhances internal control effectiveness.
- Commonly applied in financial, IT, and operational processes.
Memory trick: SoD: Separate Duties, Secure Deployment.
Continuous Security Awareness
Flip cardAn ongoing program designed to educate all employees regularly about current information security threats, policies, and best practices to maintain a strong security culture.
- Addresses evolving threat landscape.
- Reinforces security behaviors.
- Crucial for human element of security.
Memory trick: Security knowledge isn't a 'set it and forget it'; it's a 'learn and refresh it'.
Go-Live DRP Readiness
Flip cardGo-Live DRP Readiness refers to the state where the disaster recovery plan for a new system has been fully developed, integrated, and validated to ensure the system can be recovered post-implementation.
- DRP must be specific to the new system's architecture.
- Testing is crucial before production deployment.
- Ensures business continuity from day one.
Memory trick: Launch Ready? DRP Ready?
Cloud Security Oversight
Flip cardCloud security oversight involves the organization's responsibility to ensure that cloud service providers adhere to its security policies and regulatory requirements through regular audits, reviews, and contractual agreements.
- Shared responsibility model applies.
- Requires contractual security clauses.
- Verification through audits is essential.
Memory trick: Cloud security needs 'VERIFICATION' to make policy real.
Legacy System DRP Challenges
Flip cardDifficulties in developing and executing a Disaster Recovery Plan (DRP) for older, highly customized, or poorly documented systems, often due to lack of expertise, compatible hardware, or insufficient documentation.
- Knowledge drain is a major risk.
- Hardware/software compatibility issues.
- Generic DRP steps are insufficient.
Memory trick: Old systems, new problems for DRP.
IT-Business Alignment
Flip cardThe process of ensuring that IT strategies, initiatives, and operations are integrated with and support the organization's overarching business goals and objectives.
- Crucial for maximizing IT value.
- Requires strong governance and communication.
- Prevents IT projects from becoming 'solutions looking for a problem'.
Memory trick: Govern well, business thrives, IT aligns.
Business-IT Alignment
Flip cardBusiness-IT alignment ensures that IT strategies, projects, and operations are consistent with and support the organization's overall business objectives and priorities.
- Critical for achieving business value from IT investments.
- Requires active involvement of business stakeholders.
- Ensures IT solutions meet actual business needs.
Memory trick: Building a bridge without knowing the other side leads to a bridge to nowhere.
Outsourcing Performance Monitoring
Flip cardThe process of continually tracking and evaluating an outsourced service provider's performance against agreed-upon service level agreements (SLAs) and contractual obligations.
- Ensures value for money and service quality.
- Requires defined metrics and reporting mechanisms.
- Critical for managing vendor risk and accountability.
Memory trick: Trust but verify, especially with outsourcing.
Vendor Proposal Evaluation Criteria
Flip cardVendor proposal evaluation criteria are the standards used to assess and compare bids from potential suppliers for system acquisition, ensuring the chosen solution best meets organizational needs.
- Should be defined before proposals are received.
- Includes functional, technical, financial, and support aspects.
- Critical business requirements are usually weighted highest.
Memory trick: Requirements Rule, Everything Else Follows.
Access Revocation
Flip cardAccess revocation is the immediate removal of all system and data access rights for an employee upon their termination or change in role, as a critical security control measure.
- Prevents unauthorized access.
- Reduces insider threat risk.
- Must be a timely and documented process.
Memory trick: Secure the 'EXIT' to prevent unauthorized access.
Software Maintenance Controls
Flip cardProcesses and procedures designed to ensure that changes to existing software systems are authorized, tested, and implemented in a controlled manner.
- Includes change management, testing, and documentation.
- Critical for system stability and security.
- Applies to bug fixes, enhancements, and patches.
- Should mirror SDLC principles for changes.
Memory trick: Untested Fixes: Fatal Flaws.
CISO Reporting Structure
Flip cardThe hierarchical placement of the Chief Information Security Officer (CISO) within an organization, which significantly impacts the CISO's authority, independence, and effectiveness in managing information security risks.
- Ideal reporting lines include CEO, CRO, or Board.
- Reporting to CIO can create conflicts of interest.
- Independence is crucial for objective security oversight.
Memory trick: The CISO's shield protects best when not tied to the IT engine.
Security in Agile SDLC
Flip cardEmbedding security practices and considerations throughout all phases of an Agile development lifecycle, rather than as a separate, late-stage activity.
- Known as 'shifting left' security.
- Includes continuous threat modeling, secure coding, and testing.
- Reduces cost and effort of fixing vulnerabilities later.
Memory trick: Shift left for security, sprint by sprint, for agility.
Cost Performance Index (CPI)
Flip cardThe Cost Performance Index (CPI) is an Earned Value Management (EVM) metric that measures the cost efficiency of budgeted resources for work performed.
- CPI = Earned Value (EV) / Actual Cost (AC).
- A CPI < 1 indicates a cost overrun.
- A CPI > 1 indicates a cost underrun.
Memory trick: Cost Performance: Earned Value over Actual Cost.
BCP External Communication
Flip cardA robust Business Continuity Plan (BCP) must include specific procedures for communicating with external stakeholders during a disruption to manage public perception, maintain trust, and ensure compliance.
- Manages reputational risk.
- Ensures compliance with contractual/regulatory obligations.
- Maintains stakeholder confidence.
Memory trick: BCP communication is 'OUTBOUND' for reputation and rules.
Software Change Testing
Flip cardThe process of verifying that modifications to software function as intended, do not introduce new defects, and do not negatively impact existing functionality or performance before deployment.
- Prevents regressions and new defects.
- Ensures system stability and performance.
- Reduces risk of production incidents.
Memory trick: Updated code, but did you 'TEST' it right?
DRP Consistency with Capabilities
Flip cardEnsuring that a disaster recovery plan's stated objectives (RTO, RPO) are realistic and achievable given the organization's existing recovery strategies, technologies, and resources.
- Misalignment renders the DRP ineffective and misleading.
- Requires regular testing and validation of recovery capabilities.
- A critical aspect of DRP effectiveness and auditability.
Memory trick: A 'REAL' DRP ensures 'R'ecovery 'E'xpectations 'A'lign with 'L'ogistics.
Database Direct Change Risk
Flip cardThe risk that direct, unapproved, and untested changes to a production database can compromise data integrity, security, and auditability.
- Bypasses formal change management controls.
- Creates audit trail gaps.
- Increases risk of errors, data corruption, and unauthorized access.
Memory trick: Direct database changes without paperwork make for audit nightmares.
DRP Data Recovery Procedures
Flip cardDetailed, step-by-step instructions within a Disaster Recovery Plan (DRP) for backing up, restoring, and ensuring the integrity of critical data and systems following a disruptive event.
- Crucial for meeting RTOs and RPOs.
- Must account for complex interdependencies.
- Requires regular testing and validation.
Memory trick: A plan with no steps is just a wish.
Agile Requirements Validation
Flip cardThe process of continually confirming that gathered requirements accurately reflect stakeholder needs and are understood by the development team in an Agile environment.
- Uses artifacts like user stories and use cases.
- Involves continuous stakeholder feedback and collaboration.
- Ensures requirements are clear, testable, and aligned with business value.
Memory trick: For agile accuracy, stories and cases, then stakeholder faces.
Data at Rest Encryption
Flip cardData at rest encryption protects data stored on persistent storage devices (e.g., hard drives, databases, cloud storage) from unauthorized access in case of physical theft, system compromise, or unauthorized access to the storage medium.
- Protects data when not actively moving or being used.
- A fundamental control for data confidentiality.
- Essential for compliance with many data protection regulations.
Memory trick: Leaving your valuables in an unlocked safe; if someone gets in, they're gone.
Emergency Change Control
Flip cardEmergency change control refers to the process for managing urgent, unplanned changes to a system that must be implemented quickly to resolve critical issues.
- Requires expedited approval and implementation.
- Risk of bypassing standard procedures is high.
- Post-implementation review is crucial.
Memory trick: Act Fast, Test First, Stay Safe.
Pre-Employment Screening
Flip cardPre-employment screening, including background checks, should be completed and reviewed before granting new employees access to sensitive systems or information to mitigate security and integrity risks.
- A preventive control to mitigate insider threats.
- Should precede access to critical resources.
- Verifies suitability and trustworthiness of candidates.
Memory trick: Don't hand out the keys before checking the driver's license.
Emergency Change Post-Review
Flip cardA critical step after an emergency change to validate its effectiveness, assess its impact, and ensure system integrity and stability.
- Compensates for bypassed standard controls.
- Includes full testing and impact analysis.
- Ensures the system returns to a controlled state.
Memory trick: After the emergency, review to ensure no new urgency.
Cloud DRP Integration
Flip cardIntegrating cloud service provider (CSP) responsibilities and recovery procedures into an organization's disaster recovery plan (DRP) is essential for ensuring business continuity for cloud-hosted assets.
- DRP must cover all critical systems, on-premise and cloud.
- Shared responsibility model in cloud environments.
- RTO/RPO targets depend on CSP's recovery capabilities and contract.
Memory trick: Don't just float in the cloud; have a parachute plan for disaster.
Simple Payback Period
Flip cardA capital budgeting technique that calculates the time required for an investment to generate cash inflows sufficient to recover its initial cost.
- Ignores time value of money.
- Focuses on liquidity.
- Calculated by summing annual cash inflows until initial investment is recovered.
- Useful for quick screening of projects.
Memory trick: Payback: Recover Costs, Count Years.
Schedule Performance Index (SPI)
Flip cardA measure of project schedule efficiency, calculated as the ratio of Earned Value (EV) to Planned Value (PV).
- SPI > 1 indicates ahead of schedule.
- SPI < 1 indicates behind schedule.
- SPI = 1 indicates on schedule.
Memory trick: SPI: See Progress, Is it on time?
Internal Control Objectives
Flip cardInternal control objectives for IT operations define the desired state for the security, integrity, availability, and efficiency of information systems and data within an organization.
- Guides daily IT activities.
- Protects organizational assets.
- Forms the basis for internal audits.
Memory trick: Balance 'EXTERNAL' rules with 'INTERNAL' controls to shield assets.
Policy Clarity and Definitions
Flip cardInformation security policies must clearly define terms, classifications, and responsibilities to ensure employees understand and can comply with their obligations.
- Reduces ambiguity and potential for misinterpretation.
- Enables consistent application of security controls.
- Crucial for effective employee security awareness.
Memory trick: A 'CLEAR' policy ensures 'C'ompliance, 'L'egibility, 'E'mployee 'A'wareness, and 'R'esponsibility.
Cloud Security Policy
Flip cardInformation security policies specifically adapted or developed for cloud computing environments, addressing unique aspects like shared responsibility models, data residency, vendor management, and cloud service configurations.
- Must reflect shared responsibility model.
- Covers cloud-specific risks and controls.
- Integrates with overall security governance.
Memory trick: Old policy, new cloud, big risks.
System Interoperability
Flip cardSystem interoperability refers to the ability of different information systems, applications, or software to communicate, exchange, and use data in a coordinated manner.
- Crucial for integrated business processes.
- Often relies on APIs, standard protocols, or middleware.
- Lack of interoperability leads to data silos and manual effort.
Memory trick: Cloud talks to On-Premise, or it's chaos.
IT Steering Committee Role
Flip cardAn IT steering committee is a group responsible for guiding IT strategy, overseeing major IT investments, and ensuring IT initiatives support business objectives.
- Provides strategic direction for IT.
- Ensures alignment of IT with business goals.
- Approves major IT projects and budgets.
Memory trick: The IT compass must point to the business stars, not just daily tasks.
Emergency Change Post-Implementation Review
Flip cardA rapid assessment conducted shortly after an emergency change to a system to verify its effectiveness, identify any unintended consequences, and ensure stability.
- Mitigates risks from rushed changes.
- Ensures system stability post-change.
- Identifies and addresses adverse impacts quickly.
Memory trick: Emergency change: Review fast, fix faster!
IT-Business Strategic Alignment
Flip cardThe process of ensuring that IT strategies, plans, and investments are directly linked to and support the overall business goals and objectives of an organization.
- Crucial for IT value delivery.
- Prevents IT from becoming an 'island'.
- Requires continuous communication between IT and business.
Memory trick: IT's 'rocket' needs a business 'mission' to avoid just burning fuel.
IT Governance Risk Management
Flip cardIT governance includes establishing frameworks and processes for identifying, assessing, mitigating, and monitoring IT-related risks to support business objectives.
- Requires clear risk escalation paths.
- Integrates IT risk into enterprise risk management.
- Ensures timely decision-making on IT risks.
Memory trick: IT Governance 'SARP's' its way to success: Strategic, Acquisition, Risk, Performance.
Software Composition Analysis (SCA)
Flip cardA process and toolset used to identify and manage open-source and third-party components within a codebase, detecting known vulnerabilities and licensing issues.
- Addresses risks from external libraries.
- Identifies known vulnerabilities (CVEs).
- Helps manage licensing compliance.
Memory trick: Open-source, open-eyes for SCA!
Business Impact Analysis (BIA)
Flip cardA Business Impact Analysis (BIA) identifies and evaluates the potential effects of business disruptions, determining critical business functions, their dependencies, and establishing Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
- Foundation for BCP and DRP.
- Identifies critical business functions.
- Defines RTOs and RPOs based on business needs.
Memory trick: Without a map, even the fastest car can't reach the right destination.
System Integration Focus
Flip cardEnsuring different information systems can communicate, exchange data, and operate together seamlessly.
- Requires well-defined interfaces and data formats.
- Critical for avoiding data silos and manual reconciliation.
- Involves technical standards, protocols, and data mapping.
Memory trick: To link systems, look at the documentation, not just the decoration.
BCP Communication Protocols
Flip cardPredefined procedures within a Business Continuity Plan (BCP) that outline how an organization will communicate with internal and external stakeholders during and after a business disruption.
- Crucial for managing stakeholder expectations.
- Helps maintain public trust and reputation.
- Includes contact lists, messaging, and communication channels.
Memory trick: In a crisis, speak clearly, or your reputation will disappear yearly.
DRP Maintenance and Testing
Flip cardRegular review, update, and testing of the Disaster Recovery Plan (DRP) to ensure its continued relevance, accuracy, and effectiveness in recovering IT systems and data after a disruptive event.
- DRP is a living document, not static.
- Changes in IT environment necessitate updates.
- Testing validates assumptions and identifies gaps.
Memory trick: Old plan, new systems, big problems.
Database Change Controls
Flip cardMeasures implemented to ensure that modifications to database schemas, data, or configuration are authorized, tested, and tracked to maintain integrity and availability.
- Includes change management, version control, and logging.
- Critical for data integrity and system stability.
- Direct production changes are high-risk.
- Strong detective controls are essential for 'break-fix' models.
Memory trick: Break-Fix: Log Everything, Catch Anything.
Information Security Policy Development
Flip cardThe structured process of creating formal documents that outline an organization's stance on information security, defining rules, responsibilities, and expected behaviors.
- Driven by risk assessment.
- Requires management approval.
- Communicated to all stakeholders.
Memory trick: Build your security policy house on a solid risk assessment foundation.
Go-Live Readiness Assessment
Flip cardThe final evaluation before deploying a new system to production, assessing its preparedness across technical, operational, security, and business aspects.
- Includes review of testing results, defect resolution, and training.
- Critical for high-risk systems.
- Unresolved high-severity defects typically warrant delay.
- Focuses on minimizing post-implementation risks.
Memory trick: Critical Go-Live: Defects Delay.
Principle of Least Privilege
Flip cardA security principle that dictates that a user, program, or process should be given only the minimum set of permissions necessary to perform its job or function, and no more.
- Reduces the attack surface.
- Limits potential damage from compromises or errors.
- Requires careful access control management.
Memory trick: Too many keys, too many risks.
User Role Matrix Review
Flip cardThe process of defining and reviewing user roles and associated privileges within an information system to ensure adherence to the principle of least privilege and security policies.
- Should involve both business owners and IT security.
- Aims to prevent excessive access rights.
- Critical for data confidentiality, integrity, and availability.
- Part of access control design and implementation.
Memory trick: Roles Unchecked? Risks Unleashed!
BCP Roles & Responsibilities
Flip cardClearly defined assignments of duties and authority within a Business Continuity Plan (BCP) to ensure effective activation, coordination, and execution of recovery efforts during a disruption.
- Crucial for efficient response.
- Minimizes confusion and delays.
- Includes incident command structure.
Memory trick: A great plan without clear roles is like a script without actors.
Manual Data Manipulation Risk
Flip cardThe risk associated with data being processed or altered outside of automated, controlled system environments, leading to potential inaccuracies and audit trail gaps.
- Compromises data integrity and accuracy.
- Breaks the automated audit trail.
- Increases risk of human error and fraud.
Memory trick: After launch, watch for manual gaps, they hide the traps.
Disaster Recovery Plan (DRP) Testing
Flip cardDRP testing involves simulating a disaster scenario to validate the effectiveness of the disaster recovery plan and identify any weaknesses or gaps.
- Essential for ensuring business continuity.
- Types include walkthroughs, simulations, and full interruptions.
- Should be conducted regularly and documented.
Memory trick: No Drill, No Recovery, No Time.
IT Reporting Structure Impact
Flip cardThe reporting structure of the IT department significantly influences the organization's ability to integrate IT strategy with business objectives and manage IT risks effectively, depending on the reporting executive's understanding of IT.
- Reporting executive's expertise impacts IT governance quality.
- Influences IT's strategic alignment and risk management.
- Should ensure IT risks are understood at a senior level.
Memory trick: A financial captain can steer the ship, but a tech captain knows the cyber-storms.
User Acceptance Testing (UAT)
Flip cardUser Acceptance Testing (UAT) is the final stage of testing where actual users verify that the system meets business requirements and is suitable for deployment.
- Performed by end-users or client representatives.
- Focuses on validating business requirements.
- Crucial for ensuring system usability and functionality.
Memory trick: Users Accept, Business Benefits.