ISACA Certified Information Systems Auditor (CISA) Exam flashcards
185 free flashcards. Tap a card to flip it.
Problem Management
Flip cardThe process responsible for managing the lifecycle of all problems, aiming to prevent incidents from happening and to minimize the impact of incidents that cannot be prevented.
- Distinguished from incident management (which focuses on restoring service).
- Involves root cause analysis.
- Key to continuous service improvement.
Memory trick: Incidents are fires, problems are the arsonist; put out the fire, then catch the arsonist.
Business Continuity Risk
Flip cardThe potential for significant disruption to business operations and loss of data due to system failures or disasters, especially when recovery mechanisms are unproven.
- Impacts operational resilience.
- Can lead to financial and reputational damage.
- Mitigated by tested DRP/BCP.
Memory trick: Untested recovery is like a parachute you've never opened: a huge risk when you need it most.
Regulatory Compliance Audit
Flip cardAn audit focused on assessing an organization's adherence to relevant laws, regulations, and industry standards.
- Protects against legal penalties.
- Ensures ethical and responsible operations.
- Often mandated for specific industries.
Memory trick: When planning, always check the 'rulebook' first.
Inherent Risk
Flip cardThe risk that exists in the absence of any controls, representing the raw exposure to potential loss or harm.
- Exists before considering any mitigating controls.
- Determined by the nature of the business, assets, and threats.
- High inherent risk requires strong controls to reduce residual risk.
Memory trick: Inherent risk is the raw danger, before any safety nets.
Integrated Test Facility (ITF)
Flip cardAn audit technique where fictitious transactions are processed through the client's live system, alongside actual transactions, to test system controls and processing accuracy.
- Tests live system functionality.
- Allows for precise prediction of results.
- Does not interfere with real data.
Memory trick: ITF is like a 'ghost test' in the live system; you know what the ghost should do.
Problem Identification (Problem Management)
Flip cardProblem identification in IT Problem Management is the process of detecting and understanding the underlying causes (problems) of one or more incidents, which aims to prevent future recurrences.
- Distinguished from incident management (service restoration).
- Focuses on root cause analysis.
- Often triggered by recurring incidents.
Memory trick: Problem Management: Find the 'P'roblem, 'P'revent Recurrence
Reactive Maintenance Financial Impact
Flip cardThe increased monetary expenditure resulting from solely addressing system failures after they occur, encompassing repair costs, lost productivity, and potential business losses.
- Often more expensive than proactive maintenance.
- Contributes to higher Total Cost of Ownership (TCO).
- Leads to unpredictable expenses and operational disruptions.
Memory trick: Paying for emergency room visits is more expensive than regular check-ups.
Problem Identification
Flip cardThe initial step in addressing recurring operational issues, focusing on gathering evidence and understanding the 'what' and 'why' before moving to 'how to fix'.
- Crucial for effective problem resolution.
- Involves analyzing logs, procedures, and historical data.
- Precedes solution design and implementation.
Memory trick: Don't just fix it, understand why it's broken first.
Control Risk
Flip cardControl risk is the risk that a material misstatement or error in information systems or financial statements will not be prevented, or detected and corrected, on a timely basis by the entity's internal control system.
- Directly relates to the effectiveness of an organization's internal controls.
- High control risk indicates weak or absent controls.
- IS auditors assess control risk to determine the nature, timing, and extent of substantive testing.
Memory trick: I Can't Detect Anything - that's Audit Risk!
Data Migration Testing
Flip cardData migration testing is a crucial audit procedure that verifies the successful, accurate, and complete transfer of data from source systems to a new target system during system implementations or upgrades.
- Ensures data integrity and consistency post-migration.
- Involves comparing data elements, counts, and totals between source and target.
- Essential for systems integrating data from multiple sources.
Memory trick: Data Integrity: Compare, Validate, Reconcile!
User Acceptance Testing (UAT) Data
Flip cardData used in User Acceptance Testing (UAT) should be representative of production data to ensure the system behaves as expected in real-world scenarios, while also adhering to privacy and security requirements.
- Should mimic production data complexity and volume.
- Often requires anonymization or synthetic generation for sensitive data.
- Critical for identifying real-world business process issues.
Memory trick: UAT: Users Accept Testing with Accurate Data
BCP/DRP in Cloud Environments
Flip cardBusiness Continuity Plans (BCPs) and Disaster Recovery Plans (DRPs) must explicitly address the unique challenges and dependencies associated with cloud service providers, including service outages, data recovery from the cloud, and failover strategies.
- Cloud reliance shifts some BCP/DRP responsibilities to the provider.
- Organizations must understand the cloud provider's BCP/DRP capabilities (e.g., via SOC reports).
- Lack of cloud-specific provisions can lead to significant operational downtime.
Memory trick: Cloud Outage: Plan or Face Long Delays!
CMDB Relationship Gap
Flip cardA weakness in a Configuration Management Database where individual Configuration Items (CIs) are recorded, but their critical relationships and interdependencies are not adequately documented or maintained.
- Hinders effective change management.
- Impairs incident and problem resolution.
- Reduces visibility into system architecture and risk.
Memory trick: Having a list of all the players but no team roster showing who plays with whom.
Archived Data Integrity Risk
Flip cardThe danger that data moved to an archive system may become corrupt, unreadable, or otherwise unusable over time, especially if its recoverability and integrity are not regularly verified.
- Compromises legal and regulatory compliance.
- Undermines historical business intelligence.
- Regular testing is crucial for data assurance.
Memory trick: Storing old documents in a box in the attic, but never checking if they're still legible.
Single Point of Failure (SPOF)
Flip cardA component of a system that, if it fails, will stop the entire system from working. SPOFs are critical vulnerabilities in system design.
- Lack of redundancy is a key indicator.
- Can lead to complete system outage.
- Mitigated through fault tolerance and high availability designs.
Memory trick: One old server, if it goes down, takes the whole bank to town.
Data Residency Requirements
Flip cardLegal or regulatory stipulations that mandate specific data, particularly personal or sensitive information, must be stored and processed within the geographical boundaries of a particular country or region.
- Driven by national data protection laws (e.g., GDPR, CCPA).
- Impacts cloud service provider selection and configuration.
- Non-compliance can result in significant fines and legal action.
Memory trick: Data's home matters; if it roams, fines will foam.
Hot Site
Flip cardA fully equipped off-site data center that can be used immediately or with minimal setup for disaster recovery, providing a near real-time recovery capability.
- Provides the fastest recovery time among recovery site options.
- Requires significant upfront and ongoing costs.
- Relies heavily on robust contracts and regular testing with the provider.
Memory trick: An old hot site contract is like an old fire extinguisher; it might not work when you need it most.
Data Retention Policy Compliance
Flip cardData Retention Policy Compliance ensures that data is stored for the legally and operationally required duration, balancing regulatory obligations, business needs, and data minimization principles.
- Driven by legal, regulatory, and business requirements.
- Affects backup schedules and archiving strategies.
- Non-compliance can lead to fines and legal issues.
Memory trick: Retention: 'R'eally 'E'nsure 'T'hat 'E'verything 'N'eeds 'T'o 'I'nclude 'O'bligations 'N'ow
Recovery Team Activation Risk
Flip cardThe danger that, despite having a BCP, the actual recovery efforts will be hampered by the lack of clear procedures for mobilizing and directing the personnel responsible for execution.
- Critical for effective BCP execution.
- Ensures timely and coordinated response.
- Lack thereof leads to prolonged downtime.
Memory trick: A great recipe needs a chef who knows how to cook.
Data Retention Policy
Flip cardA documented policy outlining how long specific types of data must be kept to meet legal, regulatory, and business requirements.
- Ensures compliance with laws and regulations.
- Balances business needs with storage costs.
- Specifies data types, retention periods, and disposal methods.
Memory trick: Ignoring retention rules invites legal woes and big fines.
Minimizing Audit Disruption
Flip cardMinimizing audit disruption involves selecting audit procedures and approaches that gather sufficient appropriate evidence while having the least possible impact on an organization's ongoing business operations and systems.
- Balance audit objectives with operational needs.
- Utilize non-intrusive techniques where possible.
- Plan and communicate audit activities effectively.
Memory trick: Efficient Audits: CAATS Cut Costs And Time.
Communicating Audit Results to Management
Flip cardEffective communication of audit results to management involves tailoring the message to their perspective, focusing on business impact, and providing clear, actionable recommendations to facilitate understanding and prompt corrective action.
- Senior management prioritizes business risk and financial impact.
- Technical details should be summarized or presented separately for technical teams.
- Clear, concise language and actionable recommendations are crucial.
Memory trick: Reports Must Be Clear, Concise, and Impactful for Action!
Automated Deployment Gates
Flip cardAutomated deployment gates are technical controls within a CI/CD pipeline that enforce mandatory quality checks, security scans, and testing stages before code can progress to the next environment or production, preventing manual bypasses.
- Enforces consistency and quality.
- Reduces human error and process shortcuts.
- Integral to DevOps and secure software delivery.
Memory trick: Automate the Gates: No Skipping Allowed!
Untested Changes Risk
Flip cardThe inherent danger of deploying modifications to production systems without prior validation in a controlled, non-production environment.
- Directly impacts system stability and availability.
- Can introduce new bugs or security vulnerabilities.
- Increases the likelihood of service disruption and downtime.
Memory trick: Don't jump in the pool before checking the water depth.
Third-Party Assurance (SOC Reports)
Flip cardSystem and Organization Controls (SOC) reports are independent audit reports that provide information about the controls at a service organization relevant to user entities' internal control over financial reporting (SOC 1) or security, availability, processing integrity, confidentiality, or privacy (SOC 2).
- SOC 2 reports are for non-financial reporting controls (e.g., security).
- Type 2 reports cover operating effectiveness over a period.
- Provides independent assurance, reducing need for direct audits.
Memory trick: Trust the SOC: Service Organizations Certify Controls.
Configuration Baseline
Flip cardA documented and agreed-upon specification for a configuration item (CI) at a specific point in time, serving as a reference for future changes or comparisons.
- Defines the 'known good' state of a system or component.
- Used to detect unauthorized changes or deviations.
- Essential for maintaining system integrity and security.
Memory trick: No baseline is like having no blueprint; you can't tell if the building has changed.
Data Integrity
Flip cardData integrity refers to the accuracy, consistency, and reliability of data over its entire lifecycle. It ensures that data is maintained in its correct and complete form and is not altered or corrupted.
- Crucial for data quality and trustworthiness.
- Violated by inconsistencies, errors, or unauthorized changes.
- Supported by validation rules, consistency checks, and master data management.
Memory trick: Data Quality: 'C'onfidentiality, 'I'ntegrity, 'A'vailability
Sufficiency and Reliability of Audit Evidence
Flip cardSufficiency refers to the quantity of audit evidence, while reliability refers to its quality, trustworthiness, and ability to support audit conclusions.
- Sufficiency is judged by the amount of evidence.
- Reliability is influenced by source (independent vs. internal), nature (original vs. copy), and method of collection.
- Evidence from independent sources is generally more reliable.
- Direct evidence is more reliable than indirect evidence.
Memory trick: Enough evidence, but is it true?
Disaster Recovery Communication Plan
Flip cardA component of the DRP that outlines how an organization will communicate with all relevant internal and external stakeholders during and after a disaster event.
- Ensures timely and accurate information dissemination.
- Maintains stakeholder confidence.
- Addresses legal and regulatory disclosure requirements.
Memory trick: Silence in a storm sinks the ship of trust.
Staging Environment
Flip cardA non-production environment that closely mimics the production environment, used for final testing of applications and systems before deployment to live operations.
- Reduces the risk of introducing defects into production.
- Allows for realistic performance and integration testing.
- A critical step in a robust release management process.
Memory trick: No staging ground means jumping straight into the battle, with all the risks.
External Dependency Management (DRP)
Flip cardManaging external dependencies in a Disaster Recovery Plan (DRP) involves identifying critical third-party services, understanding their recovery capabilities, establishing communication protocols, and integrating their recovery into the overall DRP.
- Crucial for modern hybrid IT environments.
- Includes cloud providers, telecom, payment gateways.
- Requires clear communication and coordination plans.
Memory trick: DRP: Don't Rely Purely on Internal Parts
Audit Procedure - Evidence Gathering
Flip cardAudit procedures are the specific tasks performed by an auditor to obtain sufficient appropriate audit evidence to form an opinion on the subject matter.
- Evidence must be sufficient (quantity) and appropriate (quality/relevance).
- Methods include inquiry, observation, inspection, recalculation, re-performance, and analytical procedures.
- Documentation of procedures and evidence is critical.
Memory trick: Inspect, Observe, Inquire: IOI for evidence.
Audit Report - Executive Summary
Flip cardA concise and high-level overview of an audit report, highlighting the most significant findings, risks, and recommendations for senior management and stakeholders.
- Located at the beginning of the report.
- Focuses on strategic implications and business impact.
- Designed for quick comprehension by busy executives.
- Should be understandable without reading the full report.
Memory trick: The Executive Summary is the 'front page news' for management.
Audit Finding Documentation
Flip cardThe formal process of recording identified control weaknesses, non-compliance, or deviations from established standards, along with their potential impact.
- Ensures clear communication of issues.
- Provides evidence for recommendations.
- Forms the basis for management response.
Memory trick: Audit findings are like puzzle pieces; first, you find them, then you see their place in the big picture.
Audit Planning - System Understanding
Flip cardThe crucial initial phase where an IS auditor gains a detailed comprehension of the system under review, including its objectives, components, and operational environment.
- Forms the basis for risk assessment.
- Essential for defining audit scope and objectives.
- Informs the selection of audit methodologies and tools.
Memory trick: Plan Smart, Understand First, Then Act.
Relevance of Audit Findings
Flip cardAudit findings are relevant if they are pertinent, significant, and directly relate to the audit objectives, criteria, and the subject matter being audited, providing meaningful insights for stakeholders.
- Ensures findings address the core questions and risks of the audit.
- Irrelevant findings waste time and distract from critical issues.
- Findings should clearly link to impacts on business objectives or control effectiveness.
Memory trick: Findings must be FACTS: Factual, Accurate, Complete, Timely, Relevant, Specific.
BCP/DRP Maintenance & Review
Flip cardThe ongoing process of regularly reviewing, updating, and testing business continuity and disaster recovery plans to ensure their continued relevance and effectiveness.
- Incorporates lessons learned from tests and real incidents.
- Adapts to changes in technology, business processes, and risks.
- Ensures the plan remains viable and actionable.
Memory trick: A tested plan, unrefined, is a disaster waiting to unwind.
Post-Implementation Review (PIR)
Flip cardA Post-Implementation Review (PIR) is a formal evaluation conducted after a change or project has been implemented to assess its success, identify lessons learned, and ensure it achieved its objectives without adverse effects.
- Verifies intended outcomes.
- Identifies unintended consequences.
- Crucial for continuous process improvement.
Memory trick: PIR: Post-Implementation Review Reveals
Root Cause Analysis (RCA)
Flip cardA systematic process for identifying the underlying causes of problems or incidents, rather than just addressing their symptoms.
- Aims to prevent recurrence of issues.
- Involves detailed investigation and documentation.
- Crucial for continuous improvement in incident management.
Memory trick: Root causes are like bad roots, dig them out to grow better.
DRP Business Alignment Gap
Flip cardA deficiency in a Disaster Recovery Plan where technical IT recovery procedures are defined, but the connection to critical business processes and their continuity is not adequately addressed.
- Prevents effective prioritization of IT recovery.
- Leads to prolonged business disruption post-IT recovery.
- Highlights the need for BCP and DRP integration.
Memory trick: Fixing the car engine but not knowing how to drive it to the destination.
Communicating Audit Results
Flip cardCommunicating audit results involves formally presenting findings, conclusions, and recommendations to management and stakeholders in a clear, concise, and objective manner.
- Report should be timely, accurate, and constructive.
- Management's responses should be considered and, if appropriate, included.
- Purpose is to facilitate corrective action and improve controls.
Memory trick: Clear, Concise, Constructive: CCC for reports.
Change Management Testing
Flip cardThe process of verifying that proposed changes to an information system will function as intended and will not adversely affect existing systems or operations.
- Identifies compatibility issues proactively.
- Reduces risk of operational disruption.
- Ensures stability and reliability of systems after changes.
Memory trick: Test before you trust, or your system will rust.
Data Location Inventory Risk
Flip cardThe hazard of not knowing where specific types of sensitive data are stored across an organization's diverse IT landscape, leading to compliance failures and operational inefficiencies.
- Crucial for data privacy compliance (e.g., GDPR, CCPA).
- Supports effective data governance and security.
- Absence can lead to fines and reputational damage.
Memory trick: If you don't know where your treasures are, you can't protect them or show them off.
Preventive Maintenance
Flip cardScheduled and routine maintenance performed to prevent failures, extend the lifespan of equipment, and reduce unplanned downtime.
- Proactive, not reactive.
- Aims to identify and fix issues before they become problems.
- Reduces long-term costs and improves system reliability.
Memory trick: Fixing only when broken breaks the budget and the clock.
Patch Management Process
Flip cardThe systematic process of identifying, acquiring, testing, deploying, and verifying software patches to maintain system security and functionality.
- Crucial for addressing vulnerabilities and improving performance.
- Requires formal assessment, testing, and approval steps.
- Part of a broader change management framework.
Memory trick: Patching without assessment is like surgery without diagnosis; you might make things worse.
Data Reconciliation
Flip cardThe process of comparing two or more sets of data to ensure consistency and accuracy, often used after data migration or system integration.
- Verifies completeness and correctness of data transfer.
- Detects discrepancies, errors, or omissions.
- Crucial for maintaining data integrity.
Memory trick: Reconciliation is like checking your bank statement; does it match?
Qualitative Risk Assessment Consistency
Flip cardConsistent application of a qualitative risk assessment methodology ensures that risk scenarios, likelihood, and impact are evaluated uniformly across an organization, enabling accurate comparison and aggregation of risks.
- Uses descriptive categories (e.g., High, Medium, Low).
- Requires clear definitions for categories and criteria.
- Inconsistency undermines comparability and aggregation.
Memory trick: Consistent Criteria Creates Clear Comparisons.
Proactive Problem Management
Flip cardThe process of identifying and preventing future incidents by analyzing trends, identifying underlying causes, and implementing preventative actions.
- Focuses on preventing incident recurrence.
- Analyzes incident data for patterns and trends.
- Develops workarounds and permanent solutions.
Memory trick: If problems keep popping, you're not digging deep enough.
Missing Go/No-Go Risk
Flip cardThe hazard of deploying software releases to production without a formal, stakeholder-approved decision point, leading to potential quality issues, non-compliance, and business disruption.
- Ensures releases meet business and quality standards.
- Mitigates risks of deploying faulty software.
- Involves cross-functional stakeholder review.
Memory trick: Launching a rocket without checking all the pre-flight checklists.
Follow-up Audit Effectiveness
Flip cardFollow-up audits assess whether management has taken appropriate, timely, and effective corrective actions in response to previously reported audit findings and recommendations.
- Verifies implementation and effectiveness of controls.
- Ensures risks are mitigated as intended.
- Contributes to continuous improvement of the control environment.
Memory trick: Verify, Validate, Re-evaluate: VVR for follow-up.
Log Monitoring & Analysis
Flip cardThe process of systematically reviewing and analyzing system-generated logs to identify security threats, operational issues, and performance problems.
- Crucial for early detection of incidents.
- Aids in troubleshooting and performance tuning.
- Often involves automated tools (SIEM) for efficiency.
Memory trick: Logs unreviewed are like treasure maps unread; you know treasure exists but can't find it.
Audit Evidence Documentation
Flip cardThe record of audit procedures performed, evidence obtained, and conclusions reached, essential for supporting the auditor's opinion.
- Provides proof of work performed.
- Supports audit findings and conclusions.
- Mandatory for control reliance.
Memory trick: No 'paper trail', no 'proof trail'.
Data Quality Controls
Flip cardMechanisms and processes implemented to ensure the accuracy, completeness, consistency, validity, and timeliness of data throughout its lifecycle.
- Includes validation rules, mandatory fields, and data cleansing.
- Essential for reliable reporting and decision-making.
- Reduces errors and improves data integrity.
Memory trick: Garbage in, garbage out: bad data makes bad decisions.
Communicating Audit Findings to Management
Flip cardThe process of effectively conveying audit results, risks, and recommendations to stakeholders, especially senior management, in a clear, concise, and business-relevant manner.
- Focus on business impact and risk.
- Use clear, non-technical language.
- Provide actionable recommendations.
- Ensure findings are factual and supported by evidence.
Memory trick: Report findings like a business case, not a technical manual.
Data Owner
Flip cardA designated individual or group responsible for the strategic decisions regarding the data, including its classification, protection, and compliance with regulations.
- Accountable for data integrity, availability, and confidentiality.
- Approves access and establishes data usage policies.
- Ensures data meets business and regulatory requirements.
Memory trick: No data owner is like a ship without a captain; no one is ultimately responsible for its journey.
Cloud Connectivity Recovery
Flip cardThe process of restoring or re-establishing network connections to cloud-based services and resources as part of a disaster recovery plan.
- Crucial for hybrid and cloud-native environments.
- Involves DNS, VPNs, direct connect, and firewall configurations.
- Often overlooked in traditional DRPs focused on on-premise systems.
Memory trick: Recovering apps without cloud network is like having a phone with no signal.
Reactive Maintenance (Break/Fix)
Flip cardMaintenance performed in response to a system failure or defect, rather than as part of a scheduled or preventive plan.
- Often leads to unplanned downtime and high emergency costs.
- Can result in shorter asset lifespans.
- Contrasts with proactive maintenance strategies like preventive or predictive maintenance.
Memory trick: Waiting for a break to fix is like waiting for your car to die on the highway before getting an oil change.
Strategic Alignment Audit
Flip cardAn audit focused on evaluating whether IT and information security strategies support and are consistent with the overall business objectives and strategy.
- Ensures IT investments support business goals.
- Identifies gaps between strategic plans.
- Crucial for effective governance.
Memory trick: Strategic alignment is like two gears, business and security, turning perfectly together.
CMDB Interdependency Mapping
Flip cardCMDB interdependency mapping involves documenting the relationships between Configuration Items (CIs) and the business services they support, enabling impact analysis for changes, incidents, and problems.
- Crucial for incident and problem management.
- Facilitates change impact analysis.
- Enhances business service understanding and resilience.
Memory trick: CMDB: 'C'onnecting 'M'any 'D'ependencies for 'B'usiness
Auditor Objectivity
Flip cardThe ethical principle requiring auditors to be impartial and unbiased in their work, free from conflicts of interest or undue influence.
- Essential for audit credibility.
- Ensures unbiased reporting of facts.
- A cornerstone of professional ethics.
Memory trick: An auditor's report must stand tall and true, like a 'lighthouse of truth' in stormy seas.