ISACA Certified Information Systems Auditor (CISA) Exam flashcards
185 free flashcards. Tap a card to flip it.
Root Cause Analysis (RCA)
Flip cardA systematic process for identifying the underlying causes of problems or incidents, rather than just addressing their symptoms.
- Aims to prevent recurrence of issues.
- Involves detailed investigation and documentation.
- Crucial for continuous improvement in incident management.
Memory trick: Root causes are like bad roots, dig them out to grow better.
Post-Implementation Review (PIR)
Flip cardA Post-Implementation Review (PIR) is a formal evaluation conducted after a change or project has been implemented to assess its success, identify lessons learned, and ensure it achieved its objectives without adverse effects.
- Verifies intended outcomes.
- Identifies unintended consequences.
- Crucial for continuous process improvement.
Memory trick: PIR: Post-Implementation Review Reveals
BCP/DRP Maintenance & Review
Flip cardThe ongoing process of regularly reviewing, updating, and testing business continuity and disaster recovery plans to ensure their continued relevance and effectiveness.
- Incorporates lessons learned from tests and real incidents.
- Adapts to changes in technology, business processes, and risks.
- Ensures the plan remains viable and actionable.
Memory trick: A tested plan, unrefined, is a disaster waiting to unwind.
Follow-up Audit Objective
Flip cardTo verify that corrective actions have been effectively implemented and that the original risks identified in a prior audit have been adequately mitigated.
- Focuses on risk mitigation, not just recommendation adherence.
- Requires assessment of alternative controls.
- Ensures ongoing control effectiveness.
Memory trick: Follow-up: 'Did the fix work, or is there a new path to safety?'
SOC 2 Type 2 Report
Flip cardA Service Organization Control (SOC) 2 Type 2 report evaluates the design and operating effectiveness of a service organization's controls over a period of time, relevant to security, availability, processing integrity, confidentiality, or privacy.
- Issued by an independent auditor.
- Covers a specified period (e.g., 12 months).
- Focuses on non-financial reporting controls.
Memory trick: SOC's Scope Secures Service Organizations' Systems.