ISACA Certified Information Systems Auditor (CISA) Exam flashcards
185 free flashcards. Tap a card to flip it.
Cloud Security Policy
Flip cardInformation security policies specifically adapted or developed for cloud computing environments, addressing unique aspects like shared responsibility models, data residency, vendor management, and cloud service configurations.
- Must reflect shared responsibility model.
- Covers cloud-specific risks and controls.
- Integrates with overall security governance.
Memory trick: Old policy, new cloud, big risks.
Principle of Least Privilege
Flip cardA security principle requiring that a user or process be granted only the minimum access rights necessary to perform its job function, and no more.
- Reduces the attack surface and potential damage from breaches.
- Applies to all types of access: data, systems, networks.
- Requires regular review and adjustment of permissions.
Memory trick: Least Privilege: Only use the smallest key for the lock.
Manual Data Manipulation Risk
Flip cardThe risk associated with data being processed or altered outside of automated, controlled system environments, leading to potential inaccuracies and audit trail gaps.
- Compromises data integrity and accuracy.
- Breaks the automated audit trail.
- Increases risk of human error and fraud.
Memory trick: After launch, watch for manual gaps, they hide the traps.
BCP Roles & Responsibilities
Flip cardClearly defined assignments of duties and authority within a Business Continuity Plan (BCP) to ensure effective activation, coordination, and execution of recovery efforts during a disruption.
- Crucial for efficient response.
- Minimizes confusion and delays.
- Includes incident command structure.
Memory trick: A great plan without clear roles is like a script without actors.
User Role Matrix Review
Flip cardThe process of defining and reviewing user roles and associated privileges within an information system to ensure adherence to the principle of least privilege and security policies.
- Should involve both business owners and IT security.
- Aims to prevent excessive access rights.
- Critical for data confidentiality, integrity, and availability.
- Part of access control design and implementation.
Memory trick: Roles Unchecked? Risks Unleashed!
Go-Live Readiness Assessment
Flip cardThe final evaluation before deploying a new system to production, assessing its preparedness across technical, operational, security, and business aspects.
- Includes review of testing results, defect resolution, and training.
- Critical for high-risk systems.
- Unresolved high-severity defects typically warrant delay.
- Focuses on minimizing post-implementation risks.
Memory trick: Critical Go-Live: Defects Delay.
Information Security Policy Development
Flip cardThe structured process of creating formal documents that outline an organization's stance on information security, defining rules, responsibilities, and expected behaviors.
- Driven by risk assessment.
- Requires management approval.
- Communicated to all stakeholders.
Memory trick: Build your security policy house on a solid risk assessment foundation.
DRP Maintenance and Testing
Flip cardRegular review, update, and testing of the Disaster Recovery Plan (DRP) to ensure its continued relevance, accuracy, and effectiveness in recovering IT systems and data after a disruptive event.
- DRP is a living document, not static.
- Changes in IT environment necessitate updates.
- Testing validates assumptions and identifies gaps.
Memory trick: Old plan, new systems, big problems.
System Integration Focus
Flip cardEnsuring different information systems can communicate, exchange data, and operate together seamlessly.
- Requires well-defined interfaces and data formats.
- Critical for avoiding data silos and manual reconciliation.
- Involves technical standards, protocols, and data mapping.
Memory trick: To link systems, look at the documentation, not just the decoration.
Business Impact Analysis (BIA)
Flip cardA Business Impact Analysis (BIA) identifies and evaluates the potential effects of business disruptions, determining critical business functions, their dependencies, and establishing Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
- Foundation for BCP and DRP.
- Identifies critical business functions.
- Defines RTOs and RPOs based on business needs.
Memory trick: Without a map, even the fastest car can't reach the right destination.
Software Composition Analysis (SCA)
Flip cardA process and toolset used to identify and manage open-source and third-party components within a codebase, detecting known vulnerabilities and licensing issues.
- Addresses risks from external libraries.
- Identifies known vulnerabilities (CVEs).
- Helps manage licensing compliance.
Memory trick: Open-source, open-eyes for SCA!
SDLC Testing Phase
Flip cardThe phase in the System Development Life Cycle where the developed system is rigorously evaluated to identify defects, ensure functionality, and verify it meets business requirements.
- Includes unit, integration, system, and user acceptance testing.
- Aims to ensure quality and reliability.
- Precedes system deployment.
Memory trick: RDDTMI: Requirements, Design, Development, Testing, Implementation, Maintenance.
Security in SDLC (Shift Left)
Flip cardIntegrating security practices and considerations throughout all phases of the System Development Lifecycle (SDLC), rather than as a final step.
- Identifies and remediates vulnerabilities earlier.
- Reduces cost and effort of security fixes.
- Leads to more secure and resilient systems.
Memory trick: Security Last, Vulnerabilities Fast.
Security-Conscious Culture
Flip cardAn organizational environment where employees prioritize and actively participate in maintaining information security through awareness, vigilance, and adherence to security policies.
- Reduces human error as a vector for attacks.
- Complements technical controls and policies.
- Fosters a proactive security posture.
Memory trick: Culture's Core: Human Shield Against Social Snares.
Vulnerability Remediation Process Optimization
Flip cardImproving the efficiency and speed of fixing identified security vulnerabilities by streamlining workflows, reducing bureaucratic delays, and enhancing coordination between teams.
- Focuses on reducing time-to-remediate (TTR).
- Involves optimizing patch management, change control, and approval processes.
- Aims to meet defined service level agreements (SLAs) or policies.
Memory trick: The fix is ready, but the approval traffic light is stuck on red.
Network Segmentation (Internal)
Flip cardDividing a network into smaller, isolated sub-networks (segments) to restrict traffic flow and limit the impact of security breaches.
- Prevents lateral movement of attackers and malware.
- Enforces the principle of least privilege for network communication.
- Crucial for containing breaches and protecting critical assets.
Memory trick: A 'FLAT' network lets attackers 'SLIDE' everywhere.
Cloud-Based DDoS Mitigation
Flip cardA service provided by a third party that reroutes an organization's network traffic through its scrubbing centers to filter out malicious DDoS attack traffic before it reaches the target infrastructure.
- Scales to absorb massive volumetric attacks.
- Protects against various DDoS attack types.
- Operates 'upstream' from the protected network.
Memory trick: For a flood, you need a big dam, not just a small filter.
DLP Coverage Expansion
Flip cardExtending data loss prevention capabilities beyond basic network traffic to include endpoints, cloud applications, and encrypted communication channels for comprehensive data protection.
- Endpoint DLP monitors data on devices.
- Network DLP monitors data in transit.
- Cloud DLP monitors data in cloud services.
Memory trick: DLP is only watching the front door and windows, but data is sneaking out the back and through the clouds.
Backup Restoration Testing
Flip cardThe process of regularly verifying that backed-up data can be successfully restored and that systems can be brought back online using recovery procedures.
- Ensures the integrity and usability of backups.
- Identifies issues in backup media, software, or recovery procedures.
- Crucial for meeting RTO and RPO objectives.
Memory trick: Having a fire extinguisher is great, but does it actually work when you need it?
SIEM Correlation Rule & Threat Intelligence Tuning
Flip cardThe ongoing process of refining SIEM correlation rules and regularly updating threat intelligence feeds to improve threat detection accuracy and relevance.
- Essential for adapting to new attack vectors and reducing false positives.
- Ensures the SIEM can identify both known and emerging threats.
- A continuous process, not a one-time configuration.
Memory trick: Keep your SIEM's 'EYES' and 'BRAIN' sharp with constant updates.
DLP Control Testing
Flip cardThe process of actively attempting to bypass or trigger Data Loss Prevention (DLP) controls with simulated sensitive data to verify their configuration, enforcement, and alerting mechanisms.
- Provides direct evidence of control effectiveness.
- Identifies gaps in DLP rule sets.
- Crucial for ensuring data confidentiality.
Memory trick: Don't just believe the shield works; poke it with a stick.
DMZ to Internal Network Firewall Rules
Flip cardFirewall rules governing traffic flow between the demilitarized zone (DMZ) and the internal trusted network, which should be highly restrictive.
- DMZ servers should only initiate connections to internal systems on specific, required ports and protocols.
- General 'ANY' rules from DMZ to internal are severe security vulnerabilities.
- The principle of least privilege must be strictly applied to DMZ-to-internal communications.
Memory trick: Don't let the 'DMZ' directly 'INVADE' your internal 'KINGDOM'.
Cloud Key Management
Flip cardThe process of generating, storing, distributing, and revoking cryptographic keys for data encrypted in cloud environments, with a focus on customer control over these keys.
- Customer-managed keys enhance data sovereignty.
- Prevents cloud provider access to unencrypted data.
- Mitigates risks associated with provider data breaches.
Memory trick: In the cloud, your keys are your castle's ultimate defense.
Recovery Point Objective (RPO)
Flip cardThe maximum amount of data, measured in time, that an organization can afford to lose during a disaster or outage.
- Determines the frequency of data backups or replication.
- A shorter RPO requires more frequent data synchronization.
- Crucial for data integrity and business continuity planning.
Memory trick: Your RPO is how far back you're willing to rewind the clock on your data.
Security Strategy Alignment
Flip cardThe process of ensuring an organization's information security strategy directly supports its business objectives and operates within its defined risk appetite.
- Foundation for effective security.
- Guides resource allocation and control selection.
- Must adapt to organizational changes like acquisitions.
Memory trick: Align the strategy to the business, like a compass to true north.
Shift-Left Security
Flip cardThe practice of integrating security activities and testing earlier in the software development lifecycle (SDLC) to identify and remediate vulnerabilities proactively.
- Reduces the cost and effort of fixing vulnerabilities.
- Improves overall software quality and security.
- Encourages developers to adopt secure coding practices.
Memory trick: Finding bugs at the finish line means a costly re-run of the whole race.
Endpoint Security Coverage
Flip cardThe extent to which security controls (e.g., antivirus, EDR, patch management) are consistently applied and managed across all diverse computing devices (endpoints) within an organization's environment.
- Ensures uniform application of security policies.
- Reduces the attack surface by protecting all entry points.
- Critical for managing diverse OS and device types.
Memory trick: Diverse Devices, Disjointed Defense: A Recipe for Policy Peril.
Automated Identity and Access Management (IAM)
Flip cardThe use of technology to automatically manage user identities and their access privileges across an organization's systems and applications.
- Ensures timely provisioning and deprovisioning of access.
- Reduces human error and administrative overhead.
- Enhances security by enforcing consistent access policies.
Memory trick: Automatic updates keep the access gates always perfectly aligned with the employee's role.
Security Policy Framework
Flip cardA hierarchical structure of documents that guides an organization's information security efforts, typically including policies, standards, guidelines, and procedures.
- Policies are high-level statements of management intent.
- Standards provide mandatory requirements for implementing policies.
- Procedures offer step-by-step instructions for tasks.
Memory trick: Policy sets the 'WHAT', Standard sets the 'HOW MUCH', Procedure sets the 'STEP-BY-STEP'.
Master Encryption Key Protection
Flip cardThe practice of securely managing and protecting the primary encryption key used to encrypt and decrypt large volumes of data or other encryption keys.
- Compromise of a master key leads to total data compromise.
- Master keys should be stored in highly secure, encrypted environments.
- Key management systems (KMS) are crucial for master key protection.
Memory trick: One key to rule them all, one key to bind them, and in the darkness, compromise them.
MSSP Oversight & Internal Capability Building
Flip cardThe necessity for organizations to maintain active internal engagement and oversight of Managed Security Service Providers (MSSPs) to ensure effective security, build internal capabilities, and retain institutional knowledge.
- Outsourcing security doesn't eliminate the need for internal security expertise.
- Internal teams should participate in incident reviews and lessons learned.
- Helps the organization understand its unique threat landscape and risks.
- Prevents over-reliance and ensures informed strategic security decisions.
Memory trick: Don't just 'OUTSOURCE', 'LEARN' and 'GROW' your own security 'BRAIN'.
Encryption Gateway/Proxy
Flip cardA network device or software that acts as an intermediary, encrypting or decrypting traffic to ensure secure communication between systems with differing encryption capabilities.
- Facilitates secure communication for legacy systems.
- Translates or upgrades encryption protocols.
- Can enforce security policies at the network edge.
Memory trick: Old castles need a secure tunnel to talk to the modern world.
Role-Based Security Awareness Training
Flip cardSecurity awareness training customized to the specific risks, responsibilities, and daily activities of different employee roles or departments within an organization.
- Increases relevance and engagement for participants.
- Improves retention and application of security knowledge.
- Addresses specific threat vectors relevant to different job functions.
- Moves beyond generic 'one-size-fits-all' training.
Memory trick: Make training 'RELEVANT' to 'ENGAGE' the mind.
Regulatory Compliance in Security Policy
Flip cardEnsuring an organization's information security policies align with all applicable laws, regulations, and industry standards, especially when operating across multiple jurisdictions.
- Non-compliance can lead to significant legal, financial, and reputational damage.
- Requires continuous monitoring and adaptation of policies to evolving legal landscapes.
- International operations often introduce complex and conflicting regulatory requirements.
Memory trick: Global policies must 'REGULATE' local laws.
Post-Incident Impact Assessment
Flip cardThe process of evaluating the full extent of financial, operational, reputational, and legal damage caused by a security incident.
- Crucial for understanding the true cost of security breaches.
- Informs future security investment and risk management decisions.
- Often involves collecting data on direct and indirect costs, legal liabilities, and brand damage.
Memory trick: ASSESS the damage to avoid future 'COSTLY' mistakes.
Lessons Learned Process
Flip cardA formal systematic review conducted after security incidents to identify root causes, evaluate response effectiveness, and implement corrective actions to improve future security controls and incident response capabilities.
- Drives continuous improvement of the security program.
- Prevents recurrence of similar incidents.
- Essential for adapting to new threats and vulnerabilities.
Memory trick: Learn from Logs or Languish in Lagging Locks.
Signature-Based IDS Limitations
Flip cardIntrusion detection systems that rely on matching traffic patterns to known attack signatures, making them ineffective against new or unknown threats.
- Effective against known attack patterns.
- Requires frequent signature updates to remain effective.
- Cannot detect zero-day or novel attacks.
Memory trick: The old wanted poster only catches known bandits, not the new, hidden ghosts.
Vulnerability Remediation Efficiency
Flip cardA key metric in vulnerability management that measures the timeliness and completeness of addressing identified security weaknesses, particularly focusing on critical vulnerabilities within established service level objectives (SLOs).
- Directly reflects risk reduction.
- Indicates program maturity.
- Prioritizes high-impact vulnerabilities.
Memory trick: It's not how many bugs you find, but how many critical ones you fix, fast.
Endpoint Detection and Response (EDR)
Flip cardA cybersecurity solution that continuously monitors and collects data from endpoint devices (e.g., laptops, servers), detecting and investigating suspicious activities, and enabling rapid response to threats.
- Provides deep visibility into endpoint activities.
- Crucial for distributed and remote workforces.
- Enables rapid threat containment and remediation.
Memory trick: Each device is a mini-fort, and EDR is its vigilant guard.
SSO Single Point of Failure
Flip cardA vulnerability in a Single Sign-On (SSO) system where the failure of a single component or service within the SSO infrastructure leads to the unavailability of all applications and services that rely on it for authentication.
- Impacts system availability.
- Can cause widespread business disruption.
- Mitigated by high availability and redundancy.
Memory trick: One key to all doors means if the key breaks, all doors are locked.
Break-Glass Account Management
Flip cardEmergency access accounts designed to bypass normal privileged access controls in critical situations, requiring strong compensating controls like centralized logging and strict oversight.
- Bypasses standard workflows for speed in emergencies.
- Requires robust compensating controls (e.g., centralized logging, alerts).
- Usage must be thoroughly documented and reviewed post-event.
Memory trick: The emergency key lets you in, but the big eye is always watching and logging everything.
Air-Gapped OT Network Vulnerabilities
Flip cardDespite physical separation (air-gapping), operational technology (OT) networks remain vulnerable to sophisticated attacks via non-network vectors like removable media or supply chain compromises.
- Air-gapping reduces, but does not eliminate, attack vectors.
- Removable media (USB drives) are common infection points.
- Supply chain attacks can embed malware before deployment.
- Lack of internal security controls (AV, IDS) exacerbates risk post-breach.
Memory trick: Air-gaps are good, but 'Sneaky USBs' and 'Tricky Supply Chains' can still breach the 'FORTRESS'.
Break-Glass Account Security
Flip cardThe practice of securely managing, auditing, and monitoring emergency access (break-glass) accounts, which grant highly privileged access to critical systems.
- Designed for use only in emergencies when normal PAM processes fail.
- Requires stringent controls: strong authentication, strict access criteria, robust logging.
- Mandates regular auditing, review of usage logs, and periodic testing of functionality.
- Compromise of these accounts poses extreme risk.
Memory trick: Don't leave the 'EMERGENCY KEY' unchecked; it's a 'TREASURE' for thieves.
Automated SoD Analysis
Flip cardSoftware tools that analyze user roles, permissions, and transactions within systems to identify and flag violations of segregation of duties principles, preventing or detecting unauthorized or conflicting access combinations.
- Proactive detection of SoD conflicts.
- Scales to complex environments.
- Reduces manual review effort and errors.
Memory trick: Don't let one person hold all the keys to the kingdom; use a smart guard.
BYOD Security Policy
Flip cardA set of rules and guidelines governing the secure use of personally owned devices for accessing corporate resources, typically including requirements for device management, data protection, and acceptable use.
- Balances user convenience with corporate security.
- Requires strong technical and administrative controls.
- MDM is a cornerstone for enforcing security.
Memory trick: Your personal phone, our corporate data: MDM is the bridge.
Automated Configuration Management
Flip cardThe use of software tools to define, deploy, monitor, and enforce desired system configurations across an IT infrastructure, ensuring consistency, compliance, and reduced human error.
- Ensures consistent baselines.
- Scales across diverse environments.
- Automates remediation of configuration drift.
Memory trick: To keep all your machines in line, let a robot do the work.
Incident Response Communication
Flip cardThe structured exchange of information during a security incident, including internal team coordination, stakeholder notification, and external reporting, guided by predefined protocols and escalation paths.
- Ensures timely information flow.
- Prevents miscommunication and delays.
- Critical for effective incident containment and resolution.
Memory trick: When an alarm rings, clear voices and a direct path are key.
Cross-Border PII Incident Response
Flip cardSpecific procedures within an incident response plan to address security incidents involving personally identifiable information that is processed or transferred across national boundaries.
- Mandated by international data protection laws (e.g., GDPR).
- Involves specific notification, reporting, and remediation requirements.
- Non-compliance can lead to severe fines and legal consequences.
Memory trick: When PII crosses borders, the legal eagles are watching, and an incomplete plan means fines.
Physical Access Log Review
Flip cardThe systematic examination of records generated by physical access control systems (e.g., badge readers, turnstiles) to identify unauthorized entry attempts, policy violations, or suspicious activity.
- Crucial for detecting physical security breaches.
- Review frequency impacts detection timeliness.
- Supports forensic investigation.
Memory trick: If you don't check the visitor log often, you won't know who's inside.
Security Awareness Training Effectiveness
Flip cardThe degree to which security awareness training successfully changes employee behavior to reduce security risks, measured by metrics beyond just completion rates.
- Behavioral change is the ultimate goal, not just knowledge acquisition.
- Measured by phishing simulation results, incident rates, help desk tickets.
- Requires engaging content, relevant examples, and continuous reinforcement.
Memory trick: Learning the words doesn't mean you'll sing the song right; the lesson itself is off-key.
Key Management System (KMS)
Flip cardA system for managing cryptographic keys throughout their lifecycle, including generation, storage, distribution, rotation, and revocation, essential for the security of encrypted data.
- Crucial for both symmetric and asymmetric encryption schemes.
- Protects against unauthorized access to keys, which would compromise encrypted data.
- Poor key management is a common cause of encryption failures.
Memory trick: A good KMS is the 'KEY' to strong encryption.
Key Separation Principle
Flip cardThe principle that encryption keys should be stored and managed separately from the data they encrypt to prevent unauthorized access to both the data and the means to decrypt it.
- Reduces the risk of data compromise if the data storage is breached.
- Often implemented using Hardware Security Modules (HSMs) or Key Management Systems (KMS).
- A fundamental security control for data at rest and in transit.
Memory trick: Keys and Locks: Always Keep Them Apart to Secure Your Vault.
Requirements Traceability
Flip cardThe ability to track and link requirements throughout the entire software development lifecycle, from inception to deployment and testing.
- Ensures all requirements are met.
- Facilitates impact analysis of changes.
- Crucial for quality assurance and auditability.
Memory trick: Agile changes are fine, but if you can't 'trace the breadcrumbs', you're lost.
Automated Deployment Gates
Flip cardAutomated deployment gates are technical controls within a CI/CD pipeline that enforce mandatory quality checks, security scans, and testing stages before code can progress to the next environment or production, preventing manual bypasses.
- Enforces consistency and quality.
- Reduces human error and process shortcuts.
- Integral to DevOps and secure software delivery.
Memory trick: Automate the Gates: No Skipping Allowed!
Communicating Audit Results to Management
Flip cardEffective communication of audit results to management involves tailoring the message to their perspective, focusing on business impact, and providing clear, actionable recommendations to facilitate understanding and prompt corrective action.
- Senior management prioritizes business risk and financial impact.
- Technical details should be summarized or presented separately for technical teams.
- Clear, concise language and actionable recommendations are crucial.
Memory trick: Reports Must Be Clear, Concise, and Impactful for Action!
Minimizing Audit Disruption
Flip cardMinimizing audit disruption involves selecting audit procedures and approaches that gather sufficient appropriate evidence while having the least possible impact on an organization's ongoing business operations and systems.
- Balance audit objectives with operational needs.
- Utilize non-intrusive techniques where possible.
- Plan and communicate audit activities effectively.
Memory trick: Efficient Audits: CAATS Cut Costs And Time.
Data Retention Policy
Flip cardA documented policy outlining how long specific types of data must be kept to meet legal, regulatory, and business requirements.
- Ensures compliance with laws and regulations.
- Balances business needs with storage costs.
- Specifies data types, retention periods, and disposal methods.
Memory trick: Ignoring retention rules invites legal woes and big fines.
Recovery Team Activation Risk
Flip cardThe danger that, despite having a BCP, the actual recovery efforts will be hampered by the lack of clear procedures for mobilizing and directing the personnel responsible for execution.
- Critical for effective BCP execution.
- Ensures timely and coordinated response.
- Lack thereof leads to prolonged downtime.
Memory trick: A great recipe needs a chef who knows how to cook.
Data Retention Policy Compliance
Flip cardData Retention Policy Compliance ensures that data is stored for the legally and operationally required duration, balancing regulatory obligations, business needs, and data minimization principles.
- Driven by legal, regulatory, and business requirements.
- Affects backup schedules and archiving strategies.
- Non-compliance can lead to fines and legal issues.
Memory trick: Retention: 'R'eally 'E'nsure 'T'hat 'E'verything 'N'eeds 'T'o 'I'nclude 'O'bligations 'N'ow
BCP/DRP in Cloud Environments
Flip cardIn cloud environments, business continuity and disaster recovery plans must be explicitly updated to articulate the shared responsibility model, integrating the cloud provider's recovery capabilities with the organization's own recovery strategies and processes.
- Cloud introduces a shared responsibility model for security and recovery.
- BCP/DRP must address provider's RTO/RPO and recovery mechanisms.
- Testing is crucial to validate integrated plans.
Memory trick: Cloud Co-op: Coordinate, Communicate, Confirm.