Free knowledge base

ISACA Certified Information Systems Auditor (CISA) Exam — key terms, tricks & tips

Everything from the course in one searchable place: 253 entries. Use it to review before a practice test or look up a word you forgot.

253 results

Key term

CISA Domains

Five main knowledge areas covered by the exam.

Getting Started: How the Exam Works

Key term

Scaled Score

A converted score from 200-800, ensuring fairness.

Getting Started: How the Exam Works

Key term

Multiple-Choice Question

Exam question type with one best answer.

Getting Started: How the Exam Works

Key term

Computer-Based Testing (CBT)

Method of exam administration at testing centers.

Getting Started: How the Exam Works

Key term

Certification Requirements

Experience and education needed beyond passing exam.

Getting Started: How the Exam Works

Key term

Retake Policy

Rules for reattempting the exam after a failure.

Getting Started: How the Exam Works

Key term

Domain Weighting

Proportional representation of each domain on the exam.

Getting Started: How the Exam Works

Memory trick

Understanding the CISA Exam Structure and Format

To remember the CISA domains, think: 'A Good IS Auditor Protects Operations.' (Auditing, Governance, IS Acquisition, Protection, Operations).

Getting Started: How the Exam Works

Exam tip

Understanding the CISA Exam Structure and Format

Memorize the five CISA domains and their exact percentage weightings. Questions often test your knowledge of which domain a specific audit activity falls under.

Getting Started: How the Exam Works

Common mistake

Understanding the CISA Exam Structure and Format

Underestimating the importance of lower-weighted domains; all domains are critical for a holistic understanding.

Getting Started: How the Exam Works

Common mistake

Understanding the CISA Exam Structure and Format

Failing to manage time effectively during the exam, leading to rushed answers or incomplete sections.

Getting Started: How the Exam Works

Common mistake

Understanding the CISA Exam Structure and Format

Not understanding the difference between a 'correct' answer and the 'best' answer in multiple-choice questions.

Getting Started: How the Exam Works

Key term

CISA Review Manual (CRM)

The official, comprehensive textbook for CISA exam preparation.

Getting Started: How the Exam Works

Key term

QAE Database

ISACA's official database of CISA practice questions with explanations.

Getting Started: How the Exam Works

Key term

Learning Style

An individual's preferred method for absorbing and processing information.

Getting Started: How the Exam Works

Key term

Study Plan

A structured schedule outlining topics, resources, and timelines for exam prep.

Getting Started: How the Exam Works

Key term

Mock Exam

A full-length practice test taken under timed conditions to simulate the actual exam.

Getting Started: How the Exam Works

Key term

Active Recall

A study technique involving retrieving information from memory without prompts.

Getting Started: How the Exam Works

Key term

Spaced Repetition

A learning technique that increases intervals between reviews of previously learned material.

Getting Started: How the Exam Works

Memory trick

Effective CISA Study Strategies and Resource Utilization

CRM-QAE-PLAN: **C**onsult **R**eview **M**anual, **Q**uery **A**ll **E**xams, **P**lan **L**earning **A**nd **N**otes.

Getting Started: How the Exam Works

Exam tip

Effective CISA Study Strategies and Resource Utilization

The exam often tests your ability to apply knowledge, not just recall facts. Look for questions that describe scenarios and ask for the 'BEST' or 'MOST appropriate' action for an IS auditor. Always consider the auditor's role in maintaining independence and objectivity.

Getting Started: How the Exam Works

Common mistake

Effective CISA Study Strategies and Resource Utilization

Relying solely on practice questions without understanding the underlying concepts from the CRM.

Getting Started: How the Exam Works

Common mistake

Effective CISA Study Strategies and Resource Utilization

Not allocating enough time for review and spaced repetition, leading to forgetting previously learned material.

Getting Started: How the Exam Works

Common mistake

Effective CISA Study Strategies and Resource Utilization

Ignoring your learning style and using ineffective study methods that don't suit you.

Getting Started: How the Exam Works

Key term

ISACA Standards

Mandatory requirements for IT audit engagements.

Information System Auditing Process

Key term

ISACA Guidelines

Recommended best practices for applying standards.

Information System Auditing Process

Key term

Code of Professional Ethics

Principles governing professional conduct of ISACA members.

Information System Auditing Process

Key term

Due Professional Care

Applying the diligence and skill of a prudent professional.

Information System Auditing Process

Key term

Professional Competence

Possessing necessary knowledge, skills, and experience.

Information System Auditing Process

Key term

Independence

Freedom from conditions that threaten objectivity.

Information System Auditing Process

Key term

Confidentiality

Protecting sensitive information obtained during an audit.

Information System Auditing Process

Memory trick

ISACA IT Audit Standards, Guidelines, and Ethics

To remember the three types of standards, think: 'GPR' — General, Performance, Reporting. It's like a car's 'Gas, Pedal, Race' for getting the audit done!

Information System Auditing Process

Exam tip

ISACA IT Audit Standards, Guidelines, and Ethics

The CISA exam frequently tests the distinction between ISACA Standards (mandatory) and Guidelines (recommended). Remember that the Code of Professional Ethics applies to all ISACA members and CISA holders, and violations can lead to certification revocation.

Information System Auditing Process

Common mistake

ISACA IT Audit Standards, Guidelines, and Ethics

Confusing ISACA Standards (mandatory) with ISACA Guidelines (recommended).

Information System Auditing Process

Common mistake

ISACA IT Audit Standards, Guidelines, and Ethics

Underestimating the importance of the Code of Professional Ethics and its implications for certification.

Information System Auditing Process

Common mistake

ISACA IT Audit Standards, Guidelines, and Ethics

Failing to identify and disclose potential conflicts of interest, impacting auditor independence.

Information System Auditing Process

Key term

Audit Planning

Defining audit objectives, scope, and methodology.

Information System Auditing Process

Key term

Risk Assessment

Identifying and evaluating threats and vulnerabilities to IS assets.

Information System Auditing Process

Key term

Audit Program

A detailed plan outlining specific audit procedures.

Information System Auditing Process

Key term

Audit Scope

The boundaries and extent of the audit engagement.

Information System Auditing Process

Key term

Audit Objectives

Specific goals the audit aims to achieve.

Information System Auditing Process

Key term

Inherent Risk

Risk in absence of any controls.

Information System Auditing Process

Key term

Residual Risk

Risk remaining after controls are applied.

Information System Auditing Process

Key term

Chief Audit Executive (CAE)

Senior role responsible for overall audit function.

Information System Auditing Process

Memory trick

Audit Planning, Risk Assessment, and Program Development

To remember the planning steps: 'Understand Risks, Scope Objectives, Program Resources, Get Approval.'

Information System Auditing Process

Exam tip

Audit Planning, Risk Assessment, and Program Development

The CISA exam frequently tests the sequence of audit planning activities and the direct relationship between risk assessment results and the audit scope/procedures. Memorize that risk assessment *drives* the audit program.

Information System Auditing Process

Common mistake

Audit Planning, Risk Assessment, and Program Development

Failing to adequately understand the auditee's business and IT environment before defining the audit scope.

Information System Auditing Process

Common mistake

Audit Planning, Risk Assessment, and Program Development

Developing an audit program without performing a thorough risk assessment, leading to misdirected audit efforts.

Information System Auditing Process

Common mistake

Audit Planning, Risk Assessment, and Program Development

Not obtaining formal approval for the audit plan and program, which can lead to disputes or lack of support later.

Information System Auditing Process

Key term

Audit Evidence

Information used to form audit conclusions.

Information System Auditing Process

Key term

Sufficiency

Quantity of audit evidence collected.

Information System Auditing Process

Key term

Competence

Reliability and validity of audit evidence.

Information System Auditing Process

Key term

Relevance

Relationship of evidence to audit objective.

Information System Auditing Process

Key term

CAATs

Computer-Assisted Audit Techniques for data analysis.

Information System Auditing Process

Key term

Working Papers

Documentation supporting the auditor's report.

Information System Auditing Process

Key term

Chain of Custody

Documented chronological history of evidence.

Information System Auditing Process

Key term

Hashing

Cryptographic function to verify data integrity.

Information System Auditing Process

Memory trick

Evidence Collection and Documentation

To remember the attributes of good evidence, think 'SCR': Sufficient, Competent, Relevant. Like a 'SCR'atchpad for your audit notes!

Information System Auditing Process

Exam tip

Evidence Collection and Documentation

The CISA exam often tests the attributes of audit evidence: sufficiency, competence (reliability), and relevance. Memorize these three and what each means. Also, be prepared to distinguish between different evidence collection techniques.

Information System Auditing Process

Common mistake

Evidence Collection and Documentation

Failing to document the chain of custody for electronic evidence, which can invalidate its use.

Information System Auditing Process

Common mistake

Evidence Collection and Documentation

Collecting too little evidence (insufficient) or evidence that doesn't directly address the audit objective (irrelevant).

Information System Auditing Process

Common mistake

Evidence Collection and Documentation

Relying solely on testimonial evidence without corroborating it with other types of evidence.

Information System Auditing Process

Key term

Audit Report

Formal document communicating audit findings, conclusions, and recommendations.

Information System Auditing Process

Key term

Executive Summary

Brief overview of the audit's most important findings and conclusions.

Information System Auditing Process

Key term

Exit Conference

Meeting with management to discuss preliminary audit findings.

Information System Auditing Process

Key term

Recommendations

Suggested actions to address identified control weaknesses.

Information System Auditing Process

Key term

Audit Follow-up

Process of verifying that management has implemented recommendations.

Information System Auditing Process

Key term

Management Action Plan

Management's response outlining how they will address audit findings.

Information System Auditing Process

Key term

Factual Accuracy

Ensuring all statements in the report are verifiable and correct.

Information System Auditing Process

Key term

Objectivity

Presenting findings impartially, without bias or undue influence.

Information System Auditing Process

Memory trick

Reporting Audit Results and Follow-up

REPORT: R-eport findings, E-xplain impact, P-rovide recommendations, O-btain agreement, R-eview implementation, T-rack results.

Information System Auditing Process

Exam tip

Reporting Audit Results and Follow-up

The CISA exam emphasizes that audit reports must be objective, factual, constructive, and timely. Pay close attention to the distinct purposes of the executive summary vs. detailed findings, and the importance of the follow-up process.

Information System Auditing Process

Common mistake

Reporting Audit Results and Follow-up

Writing vague recommendations that are difficult for management to implement.

Information System Auditing Process

Common mistake

Reporting Audit Results and Follow-up

Failing to conduct proper follow-up, negating the value of the audit.

Information System Auditing Process

Common mistake

Reporting Audit Results and Follow-up

Including jargon or overly technical language without clear explanations.

Information System Auditing Process

Key term

IT Governance

Framework ensuring IT supports business objectives, manages risks, and delivers value.

Governance and Management of IT

Key term

COBIT

Framework for enterprise IT governance and management, widely used by auditors.

Governance and Management of IT

Key term

ITIL

Framework for managing IT services, focusing on service lifecycle.

Governance and Management of IT

Key term

Strategic Alignment

Ensuring IT plans and operations support overall business goals.

Governance and Management of IT

Key term

Value Delivery

Optimizing IT costs and demonstrating the value of IT investments.

Governance and Management of IT

Key term

Risk Management

Identifying, assessing, and mitigating IT-related risks.

Governance and Management of IT

Key term

Performance Measurement

Monitoring and reporting IT performance against established metrics.

Governance and Management of IT

Memory trick

Evaluating IT Governance Structures and Strategies

To remember the COBIT governance focus areas, think: S.V.R.R.P. - 'Strategic Value Requires Resourceful Risk Planning.'

Governance and Management of IT

Exam tip

Evaluating IT Governance Structures and Strategies

Memorize the five key focus areas of IT governance according to COBIT: Strategic Alignment, Value Delivery, Resource Management, Risk Management, and Performance Measurement. The exam often tests understanding of these specific components.

Governance and Management of IT

Common mistake

Evaluating IT Governance Structures and Strategies

Confusing IT governance (strategic oversight) with IT management (operational execution).

Governance and Management of IT

Common mistake

Evaluating IT Governance Structures and Strategies

Assuming that having an IT governance framework in place automatically means it's effective; auditors must verify implementation and effectiveness.

Governance and Management of IT

Common mistake

Evaluating IT Governance Structures and Strategies

Overlooking the importance of communication and stakeholder engagement in a successful governance strategy.

Governance and Management of IT

Key term

Segregation of Duties (SoD)

Dividing critical tasks among multiple individuals to prevent fraud or error.

Governance and Management of IT

Key term

Information Security Policy

High-level statement defining an organization's approach to protecting information assets.

Governance and Management of IT

Key term

Acceptable Use Policy (AUP)

Defines proper employee use of company IT resources and internet access.

Governance and Management of IT

Key term

Offboarding Process

Procedures for revoking access and retrieving assets when an employee leaves.

Governance and Management of IT

Key term

Organizational Chart

Visual representation of a company's structure, showing reporting lines.

Governance and Management of IT

Key term

Security Awareness Training

Educating employees on security risks and their responsibilities.

Governance and Management of IT

Memory trick

IT Org Structure, HR, and InfoSec Policies

Think 'HR-SOP' for Human Resources, Segregation of Duties, Organizational Structure, and Policies – all foundational for security!

Governance and Management of IT

Exam tip

IT Org Structure, HR, and InfoSec Policies

For the CISA exam, memorize that the ultimate responsibility for information security rests with senior management, even if they delegate operational tasks. Policies provide the 'what' and 'why', while procedures provide the 'how'.

Governance and Management of IT

Common mistake

IT Org Structure, HR, and InfoSec Policies

Confusing policies with procedures: Policies are high-level 'what' and 'why', procedures are detailed 'how'.

Governance and Management of IT

Common mistake

IT Org Structure, HR, and InfoSec Policies

Assuming documented policies are effective: Auditors must verify policies are communicated, understood, and enforced.

Governance and Management of IT

Common mistake

IT Org Structure, HR, and InfoSec Policies

Overlooking HR's role in security: HR practices (hiring, training, termination) are critical security controls.

Governance and Management of IT

Key term

Risk Appetite

The amount of risk an organization is willing to accept to achieve its objectives.

Governance and Management of IT

Key term

Preventive Control

A control designed to stop an undesirable event from occurring.

Governance and Management of IT

Key term

Detective Control

A control designed to identify an undesirable event that has already occurred.

Governance and Management of IT

Key term

Corrective Control

A control designed to minimize the impact of an event and restore functionality.

Governance and Management of IT

Key term

General Controls

Controls that apply to the overall IT environment, supporting application controls.

Governance and Management of IT

Key term

Application Controls

Controls embedded within specific business applications to ensure data integrity.

Governance and Management of IT

Memory trick

Assessing IT Risk Management and Control Frameworks

To remember the control types: P-D-C. 'Preventive Don't Cause' problems, 'Detective Discovers' problems, 'Corrective Cures' problems.

Governance and Management of IT

Exam tip

Assessing IT Risk Management and Control Frameworks

The CISA exam often distinguishes between the purpose of different control types. Memorize that preventive controls stop things, detective controls find things, and corrective controls fix things after they happen. Look for keywords like 'prevent,' 'detect,' or 'recover' in scenario questions.

Governance and Management of IT

Common mistake

Assessing IT Risk Management and Control Frameworks

Confusing the purpose of preventive vs. detective controls.

Governance and Management of IT

Common mistake

Assessing IT Risk Management and Control Frameworks

Assuming all risks can or should be eliminated, instead of managed to an acceptable level.

Governance and Management of IT

Common mistake

Assessing IT Risk Management and Control Frameworks

Failing to consider both the design and operational effectiveness of controls.

Governance and Management of IT

Key term

Business Continuity Plan (BCP)

Holistic plan to maintain critical business functions during disruptions.

Governance and Management of IT

Key term

Disaster Recovery Plan (DRP)

Subset of BCP focused on restoring IT infrastructure and systems.

Governance and Management of IT

Key term

Business Impact Analysis (BIA)

Identifies critical business functions and impact of their unavailability.

Governance and Management of IT

Key term

Recovery Time Objective (RTO)

Maximum acceptable downtime for a business function after an incident.

Governance and Management of IT

Key term

Recovery Point Objective (RPO)

Maximum acceptable data loss measured in time after an incident.

Governance and Management of IT

Key term

Hot Site

Fully equipped alternate facility for immediate operational resumption.

Governance and Management of IT

Key term

Cold Site

Basic facility with infrastructure, requiring equipment installation.

Governance and Management of IT

Key term

Warm Site

Partially equipped alternate facility, faster than cold, slower than hot.

Governance and Management of IT

Memory trick

Business Continuity & Disaster Recovery

BCP is 'Business Continues Planning' (big picture), DRP is 'Data Recovery Planning' (digital focus).

Governance and Management of IT

Exam tip

Business Continuity & Disaster Recovery

The CISA exam often distinguishes between BCP (business-focused, broader) and DRP (IT-focused, narrower). Keywords like 'critical business functions' point to BCP, while 'IT systems restoration' points to DRP. Memorize the definitions of RTO and RPO and their relationship to data loss and downtime.

Governance and Management of IT

Common mistake

Business Continuity & Disaster Recovery

Confusing BCP and DRP objectives or scope.

Governance and Management of IT

Common mistake

Business Continuity & Disaster Recovery

Failing to regularly test and update plans.

Governance and Management of IT

Common mistake

Business Continuity & Disaster Recovery

Not involving key stakeholders (business units, IT, management) in planning and testing.

Governance and Management of IT

Key term

Business Case

A structured proposal justifying an IT investment, outlining costs, benefits, and risks.

Information Systems Acquisition, Development and Implementation

Key term

Return on Investment (ROI)

A financial metric measuring the profitability of an investment relative to its cost.

Information Systems Acquisition, Development and Implementation

Key term

Net Present Value (NPV)

The present value of future cash flows minus the initial investment, adjusted for time value.

Information Systems Acquisition, Development and Implementation

Key term

Payback Period

The time required for an investment to generate enough cash flow to cover its initial cost.

Information Systems Acquisition, Development and Implementation

Key term

Qualitative Benefits

Non-monetary advantages of an IT investment, like improved satisfaction or efficiency.

Information Systems Acquisition, Development and Implementation

Memory trick

Evaluating Business Cases for IT Investments

To remember key business case components, think 'CRABS': Costs, Risks, Alternatives, Benefits, Solution.

Information Systems Acquisition, Development and Implementation

Exam tip

Evaluating Business Cases for IT Investments

The exam often tests your ability to identify what a CISA should focus on during business case review. Look for options that emphasize independence, validation of assumptions, risk assessment, and alignment with organizational strategy and controls.

Information Systems Acquisition, Development and Implementation

Common mistake

Evaluating Business Cases for IT Investments

Failing to challenge optimistic projections for benefits or underestimating costs.

Information Systems Acquisition, Development and Implementation

Common mistake

Evaluating Business Cases for IT Investments

Overlooking non-financial benefits or risks that are harder to quantify.

Information Systems Acquisition, Development and Implementation

Common mistake

Evaluating Business Cases for IT Investments

Not verifying the alignment of the IT investment with the organization's strategic objectives.

Information Systems Acquisition, Development and Implementation

Key term

Project Life Cycle

Stages a project goes through from start to finish.

Information Systems Acquisition, Development and Implementation

Key term

Project Governance

Framework for directing, managing, and holding projects accountable.

Information Systems Acquisition, Development and Implementation

Key term

Project Controls

Mechanisms to ensure a project stays on track and meets objectives.

Information Systems Acquisition, Development and Implementation

Key term

Risk Register

Document listing identified risks, their analysis, and responses.

Information Systems Acquisition, Development and Implementation

Key term

Change Management

Process for managing changes to project scope, schedule, or budget.

Information Systems Acquisition, Development and Implementation

Key term

Scope Creep

Uncontrolled expansion of project scope without adjustments.

Information Systems Acquisition, Development and Implementation

Key term

Steering Committee

Group providing guidance and oversight to a project.

Information Systems Acquisition, Development and Implementation

Memory trick

Project Management Practices and Controls Assessment

To remember the Project Life Cycle: I Plan Every Morning Carefully. (Initiation, Planning, Execution, Monitoring, Closure)

Information Systems Acquisition, Development and Implementation

Exam tip

Project Management Practices and Controls Assessment

The CISA exam often tests your understanding of the project life cycle phases and the specific controls appropriate for each. Pay close attention to the role of project governance and how it ensures alignment with business objectives and risk appetite.

Information Systems Acquisition, Development and Implementation

Common mistake

Project Management Practices and Controls Assessment

Assuming all project methodologies (e.g., Waterfall vs. Agile) require identical controls.

Information Systems Acquisition, Development and Implementation

Common mistake

Project Management Practices and Controls Assessment

Focusing solely on financial controls and neglecting quality, schedule, or risk controls.

Information Systems Acquisition, Development and Implementation

Common mistake

Project Management Practices and Controls Assessment

Failing to assess the effectiveness of project governance structure and its actual implementation.

Information Systems Acquisition, Development and Implementation

Key term

SDLC

System Development Life Cycle; structured process for building and maintaining IT systems.

Information Systems Acquisition, Development and Implementation

Key term

User Acceptance Testing (UAT)

Testing by end-users to confirm the system meets business requirements.

Information Systems Acquisition, Development and Implementation

Key term

Secure Coding Practices

Techniques used during development to minimize security vulnerabilities in code.

Information Systems Acquisition, Development and Implementation

Key term

Post-Implementation Review

Evaluation after system deployment to assess performance, benefits, and controls.

Information Systems Acquisition, Development and Implementation

Memory trick

Controls Over System Development & Maintenance

SDLC Controls: 'P-R-D-D-T-I-M' for Plan, Requirements, Design, Develop, Test, Implement, Maintain. Remember, 'Please Rarely Do Dumb Things In Meetings' to keep controls in mind!

Information Systems Acquisition, Development and Implementation

Exam tip

Controls Over System Development & Maintenance

The exam often tests your understanding of controls at specific SDLC stages. Keywords like 'requirements definition,' 'design review,' 'user acceptance testing,' 'change control board,' and 'rollback plan' are critical indicators of which control objective is being assessed.

Information Systems Acquisition, Development and Implementation

Common mistake

Controls Over System Development & Maintenance

Overlooking the importance of user involvement in requirements gathering and testing, leading to systems that don't meet business needs.

Information Systems Acquisition, Development and Implementation

Common mistake

Controls Over System Development & Maintenance

Failing to implement proper segregation of duties, especially between development and production, which can lead to unauthorized changes.

Information Systems Acquisition, Development and Implementation

Common mistake

Controls Over System Development & Maintenance

Neglecting to include security considerations and testing at every stage of the SDLC, rather than just as a final check.

Information Systems Acquisition, Development and Implementation

Key term

Readiness Assessment

Verifying all system components are prepared for deployment.

Information Systems Acquisition, Development and Implementation

Key term

Cutover Plan

Detailed strategy for transitioning to a new system.

Information Systems Acquisition, Development and Implementation

Key term

Rollback Plan

Contingency plan to revert to the old system if new fails.

Information Systems Acquisition, Development and Implementation

Key term

Post-Implementation Review (PIR)

Evaluation of a system after it's been in operation.

Information Systems Acquisition, Development and Implementation

Key term

Go-Live

The point at which a new system officially becomes operational.

Information Systems Acquisition, Development and Implementation

Key term

Lessons Learned

Documenting insights from a project to improve future ones.

Information Systems Acquisition, Development and Implementation

Memory trick

Assessing System Readiness & Post-Implementation

Ready Users Cut Over, Post-Launch Review! (Readiness, UAT, Cutover, Post-Launch Review)

Information Systems Acquisition, Development and Implementation

Exam tip

Assessing System Readiness & Post-Implementation

The CISA exam often distinguishes between different types of testing. Remember that User Acceptance Testing (UAT) is performed by end-users to validate business requirements, not by developers or QA for technical functionality. Also, understand the purpose and timing of a Post-Implementation Review (PIR).

Information Systems Acquisition, Development and Implementation

Common mistake

Assessing System Readiness & Post-Implementation

Skipping or rushing User Acceptance Testing (UAT), leading to systems that don't meet user needs.

Information Systems Acquisition, Development and Implementation

Common mistake

Assessing System Readiness & Post-Implementation

Not having a detailed and tested cutover plan, which can cause significant business disruption.

Information Systems Acquisition, Development and Implementation

Common mistake

Assessing System Readiness & Post-Implementation

Failing to conduct a Post-Implementation Review (PIR), missing opportunities to learn and optimize system value.

Information Systems Acquisition, Development and Implementation

Key term

IS Operations

Day-to-day activities to keep information systems running.

Information Systems Operations and Business Resilience

Key term

IS Maintenance

Activities to sustain and improve system functionality and performance.

Information Systems Operations and Business Resilience

Key term

Preventive Maintenance

Proactive activities to avoid system failures (e.g., patching).

Information Systems Operations and Business Resilience

Key term

Corrective Maintenance

Activities to fix defects or errors in systems.

Information Systems Operations and Business Resilience

Key term

Service Level Agreement (SLA)

Contract defining performance and availability targets.

Information Systems Operations and Business Resilience

Key term

Patch Management

Process of identifying, acquiring, testing, and applying software updates.

Information Systems Operations and Business Resilience

Memory trick

Evaluating IS Operations and Maintenance Practices

O.P.E.R.A.T.E. for Operations: Organize, Plan, Execute, Report, Analyze, Test, Evaluate.

Information Systems Operations and Business Resilience

Exam tip

Evaluating IS Operations and Maintenance Practices

The exam often tests your ability to identify control weaknesses related to IS operations and maintenance. Look for keywords like 'unauthorized changes,' 'lack of documentation,' 'no testing,' or 'manual intervention' as indicators of poor control.

Information Systems Operations and Business Resilience

Common mistake

Evaluating IS Operations and Maintenance Practices

Confusing IS operations with development activities; operations are about running, not building.

Information Systems Operations and Business Resilience

Common mistake

Evaluating IS Operations and Maintenance Practices

Overlooking the importance of documentation and formal procedures in both operations and maintenance.

Information Systems Operations and Business Resilience

Common mistake

Evaluating IS Operations and Maintenance Practices

Failing to recognize that inadequate testing of patches or changes is a major risk.

Information Systems Operations and Business Resilience

Key term

Data Management

Processes for managing data as a valuable organizational asset.

Information Systems Operations and Business Resilience

Key term

Data Governance

Policies and procedures for data use, access, and security.

Information Systems Operations and Business Resilience

Key term

Incident

An unplanned interruption or reduction in quality of an IT service.

Information Systems Operations and Business Resilience

Key term

Problem

The underlying cause of one or more incidents.

Information Systems Operations and Business Resilience

Key term

Incident Management

Restoring normal service operation quickly after an incident.

Information Systems Operations and Business Resilience

Key term

Problem Management

Preventing incidents and minimizing impact through root cause analysis.

Information Systems Operations and Business Resilience

Key term

Root Cause Analysis

Systematic process to identify the fundamental cause of a problem.

Information Systems Operations and Business Resilience

Memory trick

Data, Problem, and Incident Management Processes

Imagine a 'P' for Problem and 'I' for Incident. The 'P' is deeper, like a tree's roots, finding the source. The 'I' is immediate, like an ambulance, getting things back to normal fast.

Information Systems Operations and Business Resilience

Exam tip

Data, Problem, and Incident Management Processes

The CISA exam often distinguishes between incident and problem management. Remember: incidents are about restoring service, problems are about finding and fixing the root cause. Look for keywords like 'restore service' for incidents and 'prevent recurrence' or 'underlying cause' for problems.

Information Systems Operations and Business Resilience

Common mistake

Data, Problem, and Incident Management Processes

Confusing incident management (restoring service) with problem management (finding root cause).

Information Systems Operations and Business Resilience

Common mistake

Data, Problem, and Incident Management Processes

Failing to document incidents and problems thoroughly, hindering future analysis.

Information Systems Operations and Business Resilience

Common mistake

Data, Problem, and Incident Management Processes

Not escalating incidents appropriately based on their impact and urgency.

Information Systems Operations and Business Resilience

Key term

Configuration Management

Maintaining information about IT service components (CIs).

Information Systems Operations and Business Resilience

Key term

Configuration Item (CI)

Any component that needs to be managed to deliver an IT service.

Information Systems Operations and Business Resilience

Key term

CMDB

Database holding information about all CIs and their relationships.

Information Systems Operations and Business Resilience

Key term

Release Management

Planning and controlling the movement of releases to environments.

Information Systems Operations and Business Resilience

Key term

Deployment Management

Implementing releases into the live production environment.

Information Systems Operations and Business Resilience

Key term

Emergency Change

A change required to restore service, with expedited approval.

Information Systems Operations and Business Resilience

Memory trick

Change, Configuration, and Release Management Evaluation

CRM: Changes are Regulated, Configurations are Managed, Releases are Moved. Remember the order and the purpose!

Information Systems Operations and Business Resilience

Exam tip

Change, Configuration, and Release Management Evaluation

The CISA exam emphasizes the importance of segregation of duties, formal authorization, and comprehensive testing across all IT service management processes. Look for questions testing these controls in change, configuration, and release management.

Information Systems Operations and Business Resilience

Common mistake

Change, Configuration, and Release Management Evaluation

Confusing change management (the process of controlling changes) with configuration management (managing information about CIs).

Information Systems Operations and Business Resilience

Common mistake

Change, Configuration, and Release Management Evaluation

Underestimating the importance of an accurate and up-to-date CMDB for all IT service management processes.

Information Systems Operations and Business Resilience

Common mistake

Change, Configuration, and Release Management Evaluation

Forgetting that segregation of duties is a critical control across all three areas, especially between development, testing, and production.

Information Systems Operations and Business Resilience

Key term

Business Continuity (BC)

Maintaining essential business functions during and after a disruption.

Information Systems Operations and Business Resilience

Key term

Disaster Recovery (DR)

Recovering IT infrastructure and systems after a disaster.

Information Systems Operations and Business Resilience

Key term

Walkthrough/Tabletop Test

Discussion-based test of a BC/DR plan in a conference room setting.

Information Systems Operations and Business Resilience

Key term

Full Interruption Test

Actual shutdown of production systems and operation from recovery site.

Information Systems Operations and Business Resilience

Memory trick

Assessing BC/DR Plan Effectiveness

RTO and RPO: RTO is Time (how long till it's back?), RPO is Point (how much data can we lose up to that point?).

Information Systems Operations and Business Resilience

Exam tip

Assessing BC/DR Plan Effectiveness

The exam often tests the auditor's responsibility to ensure that BC/DR plans align with the organization's RTOs and RPOs. Keywords to spot: 'adequacy of RTO/RPO,' 'testing methodology,' and 'post-test review.'

Information Systems Operations and Business Resilience

Common mistake

Assessing BC/DR Plan Effectiveness

Assuming a plan is effective just because it exists; regular, comprehensive testing is essential.

Information Systems Operations and Business Resilience

Common mistake

Assessing BC/DR Plan Effectiveness

Confusing BC (business focus) with DR (IT focus); they are related but distinct.

Information Systems Operations and Business Resilience

Common mistake

Assessing BC/DR Plan Effectiveness

Not verifying that RTOs and RPOs are realistic and aligned with business needs.

Information Systems Operations and Business Resilience

Key term

Information Security Strategy

High-level plan for protecting information assets.

Protection of Information Assets

Key term

Information Security Governance

System for directing and controlling info security.

Protection of Information Assets

Key term

Policy

High-level mandatory statements of management intent.

Protection of Information Assets

Key term

Standard

Specific mandatory requirements for implementing policies.

Protection of Information Assets

Key term

Procedure

Detailed, step-by-step instructions for tasks.

Protection of Information Assets

Key term

Risk Tolerance

Organization's acceptable level of risk.

Protection of Information Assets

Key term

Stakeholder

Anyone with an interest or impact on the strategy.

Protection of Information Assets

Memory trick

Information Security Strategy and Governance

To remember the hierarchy: 'P'eople 'S'hould 'P'rotect. Policies (high-level), Standards (specific rules), Procedures (steps).

Protection of Information Assets

Exam tip

Information Security Strategy and Governance

The CISA exam often tests your ability to distinguish between policies, standards, and procedures. Remember: Policies are 'what' and 'why', Standards are 'how to comply', and Procedures are 'step-by-step instructions'.

Protection of Information Assets

Common mistake

Information Security Strategy and Governance

Confusing policies with procedures; policies are broad, procedures are granular.

Protection of Information Assets

Common mistake

Information Security Strategy and Governance

Assuming security strategy is solely an IT responsibility; it requires enterprise-wide involvement.

Protection of Information Assets

Common mistake

Information Security Strategy and Governance

Neglecting to align security strategy with overall business objectives, leading to misdirected efforts.

Protection of Information Assets

Key term

Least Privilege

Granting minimum necessary access rights.

Protection of Information Assets

Key term

Defense in Depth

Layering multiple security controls.

Protection of Information Assets

Key term

Separation of Duties

Dividing critical tasks among multiple people.

Protection of Information Assets

Key term

SIEM

System for security event management and analysis.

Protection of Information Assets

Key term

Vulnerability Scanning

Automated identification of security weaknesses.

Protection of Information Assets

Memory trick

Security Control Design, Implementation, and Monitoring

To remember control types: P.D.C. (Preventive, Detective, Corrective) is like a 'Police Department Car' – they try to stop crime, catch criminals, and help victims recover.

Protection of Information Assets

Exam tip

Security Control Design, Implementation, and Monitoring

The CISA exam often tests your ability to categorize controls by their function (preventive, detective, corrective) and apply design principles. Look for keywords like 'reduce likelihood' (preventive), 'identify occurrence' (detective), or 'minimize impact' (corrective).

Protection of Information Assets

Common mistake

Security Control Design, Implementation, and Monitoring

Failing to conduct a thorough risk assessment before selecting controls, leading to misaligned security investments.

Protection of Information Assets

Common mistake

Security Control Design, Implementation, and Monitoring

Implementing controls without proper testing and validation, resulting in ineffective or misconfigured safeguards.

Protection of Information Assets

Common mistake

Security Control Design, Implementation, and Monitoring

Treating security controls as a one-time implementation rather than a continuous process requiring ongoing monitoring and adaptation.

Protection of Information Assets

Key term

IAM

Framework for managing digital identities and access rights.

Protection of Information Assets

Key term

Authentication

Verifying a user's claimed identity.

Protection of Information Assets

Key term

Authorization

Determining what an authenticated user can do.

Protection of Information Assets

Key term

RBAC

Access control model based on user roles.

Protection of Information Assets

Key term

Encryption

Transforming data into ciphertext to protect it.

Protection of Information Assets

Key term

Symmetric Encryption

Uses one key for both encryption and decryption.

Protection of Information Assets

Key term

Asymmetric Encryption

Uses a public/private key pair for encryption/decryption.

Protection of Information Assets

Key term

Key Management

Secure handling of cryptographic keys.

Protection of Information Assets

Memory trick

Identity, Access, and Encryption Controls

For Access Control Models, remember 'DAMN R': Discretionary, Administrative, Mandatory, Network, Role-Based. (Focus on DAC, MAC, RBAC for the exam.)

Protection of Information Assets

Exam tip

Identity, Access, and Encryption Controls

The CISA exam frequently tests the distinction between authentication (who you are) and authorization (what you can do). Also, understand the benefits and drawbacks of symmetric versus asymmetric encryption, and the critical role of key management.

Protection of Information Assets

Common mistake

Identity, Access, and Encryption Controls

Confusing authentication with authorization; they are distinct steps in the access process.

Protection of Information Assets

Common mistake

Identity, Access, and Encryption Controls

Underestimating the importance of key management in an encryption scheme; weak key management renders strong encryption useless.

Protection of Information Assets

Common mistake

Identity, Access, and Encryption Controls

Failing to apply the principle of least privilege, granting users more access than necessary for their job functions.

Protection of Information Assets

Key term

Firewall

Network security system monitoring and controlling traffic.

Protection of Information Assets

Key term

IDS/IPS

Detects/prevents malicious network activity.

Protection of Information Assets

Key term

Endpoint Security

Protects individual devices like computers and mobile phones.

Protection of Information Assets

Key term

Incident Response Plan (IRP)

Documented procedure for handling security breaches.

Protection of Information Assets

Key term

DMZ (Demilitarized Zone)

Subnetwork exposing external-facing services securely.

Protection of Information Assets

Key term

Data Loss Prevention (DLP)

Tools preventing sensitive data from leaving the network.

Protection of Information Assets

Memory trick

Network, Endpoint Security, and Incident Management

P-I-C-E-R-L: **P**repare, **I**dentify, **C**ontain, **E**radicate, **R**ecover, **L**earn. It's like a recipe for fixing a security mess!

Protection of Information Assets

Exam tip

Network, Endpoint Security, and Incident Management

The exam often tests your understanding of the *phases* of incident response and the auditor's role in *evaluating* the effectiveness of each phase. Keywords to spot include 'preparation,' 'identification,' 'containment,' 'eradication,' 'recovery,' and 'lessons learned.' Memorize the order and what happens in each phase.

Protection of Information Assets

Common mistake

Network, Endpoint Security, and Incident Management

Confusing IDS (detection) with IPS (prevention) – remember IPS actively blocks.

Protection of Information Assets

Common mistake

Network, Endpoint Security, and Incident Management

Assuming a documented incident response plan is automatically effective without testing.

Protection of Information Assets

Common mistake

Network, Endpoint Security, and Incident Management

Overlooking the importance of patch management for endpoint security, often seen as 'basic' but critical.

Protection of Information Assets