CISA Domains
Five main knowledge areas covered by the exam.
Getting Started: How the Exam Works
Free knowledge base
Everything from the course in one searchable place: 253 entries. Use it to review before a practice test or look up a word you forgot.
253 results
Five main knowledge areas covered by the exam.
Getting Started: How the Exam Works
A converted score from 200-800, ensuring fairness.
Getting Started: How the Exam Works
Exam question type with one best answer.
Getting Started: How the Exam Works
Method of exam administration at testing centers.
Getting Started: How the Exam Works
Experience and education needed beyond passing exam.
Getting Started: How the Exam Works
Rules for reattempting the exam after a failure.
Getting Started: How the Exam Works
Proportional representation of each domain on the exam.
Getting Started: How the Exam Works
To remember the CISA domains, think: 'A Good IS Auditor Protects Operations.' (Auditing, Governance, IS Acquisition, Protection, Operations).
Getting Started: How the Exam Works
Memorize the five CISA domains and their exact percentage weightings. Questions often test your knowledge of which domain a specific audit activity falls under.
Getting Started: How the Exam Works
Underestimating the importance of lower-weighted domains; all domains are critical for a holistic understanding.
Getting Started: How the Exam Works
Failing to manage time effectively during the exam, leading to rushed answers or incomplete sections.
Getting Started: How the Exam Works
Not understanding the difference between a 'correct' answer and the 'best' answer in multiple-choice questions.
Getting Started: How the Exam Works
The official, comprehensive textbook for CISA exam preparation.
Getting Started: How the Exam Works
ISACA's official database of CISA practice questions with explanations.
Getting Started: How the Exam Works
An individual's preferred method for absorbing and processing information.
Getting Started: How the Exam Works
A structured schedule outlining topics, resources, and timelines for exam prep.
Getting Started: How the Exam Works
A full-length practice test taken under timed conditions to simulate the actual exam.
Getting Started: How the Exam Works
A study technique involving retrieving information from memory without prompts.
Getting Started: How the Exam Works
A learning technique that increases intervals between reviews of previously learned material.
Getting Started: How the Exam Works
CRM-QAE-PLAN: **C**onsult **R**eview **M**anual, **Q**uery **A**ll **E**xams, **P**lan **L**earning **A**nd **N**otes.
Getting Started: How the Exam Works
The exam often tests your ability to apply knowledge, not just recall facts. Look for questions that describe scenarios and ask for the 'BEST' or 'MOST appropriate' action for an IS auditor. Always consider the auditor's role in maintaining independence and objectivity.
Getting Started: How the Exam Works
Relying solely on practice questions without understanding the underlying concepts from the CRM.
Getting Started: How the Exam Works
Not allocating enough time for review and spaced repetition, leading to forgetting previously learned material.
Getting Started: How the Exam Works
Ignoring your learning style and using ineffective study methods that don't suit you.
Getting Started: How the Exam Works
Mandatory requirements for IT audit engagements.
Information System Auditing Process
Recommended best practices for applying standards.
Information System Auditing Process
Principles governing professional conduct of ISACA members.
Information System Auditing Process
Applying the diligence and skill of a prudent professional.
Information System Auditing Process
Possessing necessary knowledge, skills, and experience.
Information System Auditing Process
Freedom from conditions that threaten objectivity.
Information System Auditing Process
Protecting sensitive information obtained during an audit.
Information System Auditing Process
To remember the three types of standards, think: 'GPR' — General, Performance, Reporting. It's like a car's 'Gas, Pedal, Race' for getting the audit done!
Information System Auditing Process
The CISA exam frequently tests the distinction between ISACA Standards (mandatory) and Guidelines (recommended). Remember that the Code of Professional Ethics applies to all ISACA members and CISA holders, and violations can lead to certification revocation.
Information System Auditing Process
Confusing ISACA Standards (mandatory) with ISACA Guidelines (recommended).
Information System Auditing Process
Underestimating the importance of the Code of Professional Ethics and its implications for certification.
Information System Auditing Process
Failing to identify and disclose potential conflicts of interest, impacting auditor independence.
Information System Auditing Process
Defining audit objectives, scope, and methodology.
Information System Auditing Process
Identifying and evaluating threats and vulnerabilities to IS assets.
Information System Auditing Process
A detailed plan outlining specific audit procedures.
Information System Auditing Process
The boundaries and extent of the audit engagement.
Information System Auditing Process
Specific goals the audit aims to achieve.
Information System Auditing Process
Risk in absence of any controls.
Information System Auditing Process
Risk remaining after controls are applied.
Information System Auditing Process
Senior role responsible for overall audit function.
Information System Auditing Process
To remember the planning steps: 'Understand Risks, Scope Objectives, Program Resources, Get Approval.'
Information System Auditing Process
The CISA exam frequently tests the sequence of audit planning activities and the direct relationship between risk assessment results and the audit scope/procedures. Memorize that risk assessment *drives* the audit program.
Information System Auditing Process
Failing to adequately understand the auditee's business and IT environment before defining the audit scope.
Information System Auditing Process
Developing an audit program without performing a thorough risk assessment, leading to misdirected audit efforts.
Information System Auditing Process
Not obtaining formal approval for the audit plan and program, which can lead to disputes or lack of support later.
Information System Auditing Process
Information used to form audit conclusions.
Information System Auditing Process
Quantity of audit evidence collected.
Information System Auditing Process
Reliability and validity of audit evidence.
Information System Auditing Process
Relationship of evidence to audit objective.
Information System Auditing Process
Computer-Assisted Audit Techniques for data analysis.
Information System Auditing Process
Documentation supporting the auditor's report.
Information System Auditing Process
Documented chronological history of evidence.
Information System Auditing Process
Cryptographic function to verify data integrity.
Information System Auditing Process
To remember the attributes of good evidence, think 'SCR': Sufficient, Competent, Relevant. Like a 'SCR'atchpad for your audit notes!
Information System Auditing Process
The CISA exam often tests the attributes of audit evidence: sufficiency, competence (reliability), and relevance. Memorize these three and what each means. Also, be prepared to distinguish between different evidence collection techniques.
Information System Auditing Process
Failing to document the chain of custody for electronic evidence, which can invalidate its use.
Information System Auditing Process
Collecting too little evidence (insufficient) or evidence that doesn't directly address the audit objective (irrelevant).
Information System Auditing Process
Relying solely on testimonial evidence without corroborating it with other types of evidence.
Information System Auditing Process
Formal document communicating audit findings, conclusions, and recommendations.
Information System Auditing Process
Brief overview of the audit's most important findings and conclusions.
Information System Auditing Process
Meeting with management to discuss preliminary audit findings.
Information System Auditing Process
Suggested actions to address identified control weaknesses.
Information System Auditing Process
Process of verifying that management has implemented recommendations.
Information System Auditing Process
Management's response outlining how they will address audit findings.
Information System Auditing Process
Ensuring all statements in the report are verifiable and correct.
Information System Auditing Process
Presenting findings impartially, without bias or undue influence.
Information System Auditing Process
REPORT: R-eport findings, E-xplain impact, P-rovide recommendations, O-btain agreement, R-eview implementation, T-rack results.
Information System Auditing Process
The CISA exam emphasizes that audit reports must be objective, factual, constructive, and timely. Pay close attention to the distinct purposes of the executive summary vs. detailed findings, and the importance of the follow-up process.
Information System Auditing Process
Writing vague recommendations that are difficult for management to implement.
Information System Auditing Process
Failing to conduct proper follow-up, negating the value of the audit.
Information System Auditing Process
Including jargon or overly technical language without clear explanations.
Information System Auditing Process
Framework ensuring IT supports business objectives, manages risks, and delivers value.
Governance and Management of IT
Framework for enterprise IT governance and management, widely used by auditors.
Governance and Management of IT
Framework for managing IT services, focusing on service lifecycle.
Governance and Management of IT
Ensuring IT plans and operations support overall business goals.
Governance and Management of IT
Optimizing IT costs and demonstrating the value of IT investments.
Governance and Management of IT
Identifying, assessing, and mitigating IT-related risks.
Governance and Management of IT
Monitoring and reporting IT performance against established metrics.
Governance and Management of IT
To remember the COBIT governance focus areas, think: S.V.R.R.P. - 'Strategic Value Requires Resourceful Risk Planning.'
Governance and Management of IT
Memorize the five key focus areas of IT governance according to COBIT: Strategic Alignment, Value Delivery, Resource Management, Risk Management, and Performance Measurement. The exam often tests understanding of these specific components.
Governance and Management of IT
Confusing IT governance (strategic oversight) with IT management (operational execution).
Governance and Management of IT
Assuming that having an IT governance framework in place automatically means it's effective; auditors must verify implementation and effectiveness.
Governance and Management of IT
Overlooking the importance of communication and stakeholder engagement in a successful governance strategy.
Governance and Management of IT
Dividing critical tasks among multiple individuals to prevent fraud or error.
Governance and Management of IT
High-level statement defining an organization's approach to protecting information assets.
Governance and Management of IT
Defines proper employee use of company IT resources and internet access.
Governance and Management of IT
Procedures for revoking access and retrieving assets when an employee leaves.
Governance and Management of IT
Visual representation of a company's structure, showing reporting lines.
Governance and Management of IT
Educating employees on security risks and their responsibilities.
Governance and Management of IT
Think 'HR-SOP' for Human Resources, Segregation of Duties, Organizational Structure, and Policies – all foundational for security!
Governance and Management of IT
For the CISA exam, memorize that the ultimate responsibility for information security rests with senior management, even if they delegate operational tasks. Policies provide the 'what' and 'why', while procedures provide the 'how'.
Governance and Management of IT
Confusing policies with procedures: Policies are high-level 'what' and 'why', procedures are detailed 'how'.
Governance and Management of IT
Assuming documented policies are effective: Auditors must verify policies are communicated, understood, and enforced.
Governance and Management of IT
Overlooking HR's role in security: HR practices (hiring, training, termination) are critical security controls.
Governance and Management of IT
The amount of risk an organization is willing to accept to achieve its objectives.
Governance and Management of IT
A control designed to stop an undesirable event from occurring.
Governance and Management of IT
A control designed to identify an undesirable event that has already occurred.
Governance and Management of IT
A control designed to minimize the impact of an event and restore functionality.
Governance and Management of IT
Controls that apply to the overall IT environment, supporting application controls.
Governance and Management of IT
Controls embedded within specific business applications to ensure data integrity.
Governance and Management of IT
To remember the control types: P-D-C. 'Preventive Don't Cause' problems, 'Detective Discovers' problems, 'Corrective Cures' problems.
Governance and Management of IT
The CISA exam often distinguishes between the purpose of different control types. Memorize that preventive controls stop things, detective controls find things, and corrective controls fix things after they happen. Look for keywords like 'prevent,' 'detect,' or 'recover' in scenario questions.
Governance and Management of IT
Confusing the purpose of preventive vs. detective controls.
Governance and Management of IT
Assuming all risks can or should be eliminated, instead of managed to an acceptable level.
Governance and Management of IT
Failing to consider both the design and operational effectiveness of controls.
Governance and Management of IT
Holistic plan to maintain critical business functions during disruptions.
Governance and Management of IT
Subset of BCP focused on restoring IT infrastructure and systems.
Governance and Management of IT
Identifies critical business functions and impact of their unavailability.
Governance and Management of IT
Maximum acceptable downtime for a business function after an incident.
Governance and Management of IT
Maximum acceptable data loss measured in time after an incident.
Governance and Management of IT
Fully equipped alternate facility for immediate operational resumption.
Governance and Management of IT
Basic facility with infrastructure, requiring equipment installation.
Governance and Management of IT
Partially equipped alternate facility, faster than cold, slower than hot.
Governance and Management of IT
BCP is 'Business Continues Planning' (big picture), DRP is 'Data Recovery Planning' (digital focus).
Governance and Management of IT
The CISA exam often distinguishes between BCP (business-focused, broader) and DRP (IT-focused, narrower). Keywords like 'critical business functions' point to BCP, while 'IT systems restoration' points to DRP. Memorize the definitions of RTO and RPO and their relationship to data loss and downtime.
Governance and Management of IT
Confusing BCP and DRP objectives or scope.
Governance and Management of IT
Failing to regularly test and update plans.
Governance and Management of IT
Not involving key stakeholders (business units, IT, management) in planning and testing.
Governance and Management of IT
A structured proposal justifying an IT investment, outlining costs, benefits, and risks.
Information Systems Acquisition, Development and Implementation
A financial metric measuring the profitability of an investment relative to its cost.
Information Systems Acquisition, Development and Implementation
The present value of future cash flows minus the initial investment, adjusted for time value.
Information Systems Acquisition, Development and Implementation
The time required for an investment to generate enough cash flow to cover its initial cost.
Information Systems Acquisition, Development and Implementation
Non-monetary advantages of an IT investment, like improved satisfaction or efficiency.
Information Systems Acquisition, Development and Implementation
To remember key business case components, think 'CRABS': Costs, Risks, Alternatives, Benefits, Solution.
Information Systems Acquisition, Development and Implementation
The exam often tests your ability to identify what a CISA should focus on during business case review. Look for options that emphasize independence, validation of assumptions, risk assessment, and alignment with organizational strategy and controls.
Information Systems Acquisition, Development and Implementation
Failing to challenge optimistic projections for benefits or underestimating costs.
Information Systems Acquisition, Development and Implementation
Overlooking non-financial benefits or risks that are harder to quantify.
Information Systems Acquisition, Development and Implementation
Not verifying the alignment of the IT investment with the organization's strategic objectives.
Information Systems Acquisition, Development and Implementation
Stages a project goes through from start to finish.
Information Systems Acquisition, Development and Implementation
Framework for directing, managing, and holding projects accountable.
Information Systems Acquisition, Development and Implementation
Mechanisms to ensure a project stays on track and meets objectives.
Information Systems Acquisition, Development and Implementation
Document listing identified risks, their analysis, and responses.
Information Systems Acquisition, Development and Implementation
Process for managing changes to project scope, schedule, or budget.
Information Systems Acquisition, Development and Implementation
Uncontrolled expansion of project scope without adjustments.
Information Systems Acquisition, Development and Implementation
Group providing guidance and oversight to a project.
Information Systems Acquisition, Development and Implementation
To remember the Project Life Cycle: I Plan Every Morning Carefully. (Initiation, Planning, Execution, Monitoring, Closure)
Information Systems Acquisition, Development and Implementation
The CISA exam often tests your understanding of the project life cycle phases and the specific controls appropriate for each. Pay close attention to the role of project governance and how it ensures alignment with business objectives and risk appetite.
Information Systems Acquisition, Development and Implementation
Assuming all project methodologies (e.g., Waterfall vs. Agile) require identical controls.
Information Systems Acquisition, Development and Implementation
Focusing solely on financial controls and neglecting quality, schedule, or risk controls.
Information Systems Acquisition, Development and Implementation
Failing to assess the effectiveness of project governance structure and its actual implementation.
Information Systems Acquisition, Development and Implementation
System Development Life Cycle; structured process for building and maintaining IT systems.
Information Systems Acquisition, Development and Implementation
Testing by end-users to confirm the system meets business requirements.
Information Systems Acquisition, Development and Implementation
Techniques used during development to minimize security vulnerabilities in code.
Information Systems Acquisition, Development and Implementation
Evaluation after system deployment to assess performance, benefits, and controls.
Information Systems Acquisition, Development and Implementation
SDLC Controls: 'P-R-D-D-T-I-M' for Plan, Requirements, Design, Develop, Test, Implement, Maintain. Remember, 'Please Rarely Do Dumb Things In Meetings' to keep controls in mind!
Information Systems Acquisition, Development and Implementation
The exam often tests your understanding of controls at specific SDLC stages. Keywords like 'requirements definition,' 'design review,' 'user acceptance testing,' 'change control board,' and 'rollback plan' are critical indicators of which control objective is being assessed.
Information Systems Acquisition, Development and Implementation
Overlooking the importance of user involvement in requirements gathering and testing, leading to systems that don't meet business needs.
Information Systems Acquisition, Development and Implementation
Failing to implement proper segregation of duties, especially between development and production, which can lead to unauthorized changes.
Information Systems Acquisition, Development and Implementation
Neglecting to include security considerations and testing at every stage of the SDLC, rather than just as a final check.
Information Systems Acquisition, Development and Implementation
Verifying all system components are prepared for deployment.
Information Systems Acquisition, Development and Implementation
Detailed strategy for transitioning to a new system.
Information Systems Acquisition, Development and Implementation
Contingency plan to revert to the old system if new fails.
Information Systems Acquisition, Development and Implementation
Evaluation of a system after it's been in operation.
Information Systems Acquisition, Development and Implementation
The point at which a new system officially becomes operational.
Information Systems Acquisition, Development and Implementation
Documenting insights from a project to improve future ones.
Information Systems Acquisition, Development and Implementation
Ready Users Cut Over, Post-Launch Review! (Readiness, UAT, Cutover, Post-Launch Review)
Information Systems Acquisition, Development and Implementation
The CISA exam often distinguishes between different types of testing. Remember that User Acceptance Testing (UAT) is performed by end-users to validate business requirements, not by developers or QA for technical functionality. Also, understand the purpose and timing of a Post-Implementation Review (PIR).
Information Systems Acquisition, Development and Implementation
Skipping or rushing User Acceptance Testing (UAT), leading to systems that don't meet user needs.
Information Systems Acquisition, Development and Implementation
Not having a detailed and tested cutover plan, which can cause significant business disruption.
Information Systems Acquisition, Development and Implementation
Failing to conduct a Post-Implementation Review (PIR), missing opportunities to learn and optimize system value.
Information Systems Acquisition, Development and Implementation
Day-to-day activities to keep information systems running.
Information Systems Operations and Business Resilience
Activities to sustain and improve system functionality and performance.
Information Systems Operations and Business Resilience
Proactive activities to avoid system failures (e.g., patching).
Information Systems Operations and Business Resilience
Activities to fix defects or errors in systems.
Information Systems Operations and Business Resilience
Contract defining performance and availability targets.
Information Systems Operations and Business Resilience
Process of identifying, acquiring, testing, and applying software updates.
Information Systems Operations and Business Resilience
O.P.E.R.A.T.E. for Operations: Organize, Plan, Execute, Report, Analyze, Test, Evaluate.
Information Systems Operations and Business Resilience
The exam often tests your ability to identify control weaknesses related to IS operations and maintenance. Look for keywords like 'unauthorized changes,' 'lack of documentation,' 'no testing,' or 'manual intervention' as indicators of poor control.
Information Systems Operations and Business Resilience
Confusing IS operations with development activities; operations are about running, not building.
Information Systems Operations and Business Resilience
Overlooking the importance of documentation and formal procedures in both operations and maintenance.
Information Systems Operations and Business Resilience
Failing to recognize that inadequate testing of patches or changes is a major risk.
Information Systems Operations and Business Resilience
Processes for managing data as a valuable organizational asset.
Information Systems Operations and Business Resilience
Policies and procedures for data use, access, and security.
Information Systems Operations and Business Resilience
An unplanned interruption or reduction in quality of an IT service.
Information Systems Operations and Business Resilience
The underlying cause of one or more incidents.
Information Systems Operations and Business Resilience
Restoring normal service operation quickly after an incident.
Information Systems Operations and Business Resilience
Preventing incidents and minimizing impact through root cause analysis.
Information Systems Operations and Business Resilience
Systematic process to identify the fundamental cause of a problem.
Information Systems Operations and Business Resilience
Imagine a 'P' for Problem and 'I' for Incident. The 'P' is deeper, like a tree's roots, finding the source. The 'I' is immediate, like an ambulance, getting things back to normal fast.
Information Systems Operations and Business Resilience
The CISA exam often distinguishes between incident and problem management. Remember: incidents are about restoring service, problems are about finding and fixing the root cause. Look for keywords like 'restore service' for incidents and 'prevent recurrence' or 'underlying cause' for problems.
Information Systems Operations and Business Resilience
Confusing incident management (restoring service) with problem management (finding root cause).
Information Systems Operations and Business Resilience
Failing to document incidents and problems thoroughly, hindering future analysis.
Information Systems Operations and Business Resilience
Not escalating incidents appropriately based on their impact and urgency.
Information Systems Operations and Business Resilience
Maintaining information about IT service components (CIs).
Information Systems Operations and Business Resilience
Any component that needs to be managed to deliver an IT service.
Information Systems Operations and Business Resilience
Database holding information about all CIs and their relationships.
Information Systems Operations and Business Resilience
Planning and controlling the movement of releases to environments.
Information Systems Operations and Business Resilience
Implementing releases into the live production environment.
Information Systems Operations and Business Resilience
A change required to restore service, with expedited approval.
Information Systems Operations and Business Resilience
CRM: Changes are Regulated, Configurations are Managed, Releases are Moved. Remember the order and the purpose!
Information Systems Operations and Business Resilience
The CISA exam emphasizes the importance of segregation of duties, formal authorization, and comprehensive testing across all IT service management processes. Look for questions testing these controls in change, configuration, and release management.
Information Systems Operations and Business Resilience
Confusing change management (the process of controlling changes) with configuration management (managing information about CIs).
Information Systems Operations and Business Resilience
Underestimating the importance of an accurate and up-to-date CMDB for all IT service management processes.
Information Systems Operations and Business Resilience
Forgetting that segregation of duties is a critical control across all three areas, especially between development, testing, and production.
Information Systems Operations and Business Resilience
Maintaining essential business functions during and after a disruption.
Information Systems Operations and Business Resilience
Recovering IT infrastructure and systems after a disaster.
Information Systems Operations and Business Resilience
Discussion-based test of a BC/DR plan in a conference room setting.
Information Systems Operations and Business Resilience
Actual shutdown of production systems and operation from recovery site.
Information Systems Operations and Business Resilience
RTO and RPO: RTO is Time (how long till it's back?), RPO is Point (how much data can we lose up to that point?).
Information Systems Operations and Business Resilience
The exam often tests the auditor's responsibility to ensure that BC/DR plans align with the organization's RTOs and RPOs. Keywords to spot: 'adequacy of RTO/RPO,' 'testing methodology,' and 'post-test review.'
Information Systems Operations and Business Resilience
Assuming a plan is effective just because it exists; regular, comprehensive testing is essential.
Information Systems Operations and Business Resilience
Confusing BC (business focus) with DR (IT focus); they are related but distinct.
Information Systems Operations and Business Resilience
Not verifying that RTOs and RPOs are realistic and aligned with business needs.
Information Systems Operations and Business Resilience
High-level plan for protecting information assets.
Protection of Information Assets
System for directing and controlling info security.
Protection of Information Assets
High-level mandatory statements of management intent.
Protection of Information Assets
Specific mandatory requirements for implementing policies.
Protection of Information Assets
Detailed, step-by-step instructions for tasks.
Protection of Information Assets
Organization's acceptable level of risk.
Protection of Information Assets
Anyone with an interest or impact on the strategy.
Protection of Information Assets
To remember the hierarchy: 'P'eople 'S'hould 'P'rotect. Policies (high-level), Standards (specific rules), Procedures (steps).
Protection of Information Assets
The CISA exam often tests your ability to distinguish between policies, standards, and procedures. Remember: Policies are 'what' and 'why', Standards are 'how to comply', and Procedures are 'step-by-step instructions'.
Protection of Information Assets
Confusing policies with procedures; policies are broad, procedures are granular.
Protection of Information Assets
Assuming security strategy is solely an IT responsibility; it requires enterprise-wide involvement.
Protection of Information Assets
Neglecting to align security strategy with overall business objectives, leading to misdirected efforts.
Protection of Information Assets
Granting minimum necessary access rights.
Protection of Information Assets
Layering multiple security controls.
Protection of Information Assets
Dividing critical tasks among multiple people.
Protection of Information Assets
System for security event management and analysis.
Protection of Information Assets
Automated identification of security weaknesses.
Protection of Information Assets
To remember control types: P.D.C. (Preventive, Detective, Corrective) is like a 'Police Department Car' – they try to stop crime, catch criminals, and help victims recover.
Protection of Information Assets
The CISA exam often tests your ability to categorize controls by their function (preventive, detective, corrective) and apply design principles. Look for keywords like 'reduce likelihood' (preventive), 'identify occurrence' (detective), or 'minimize impact' (corrective).
Protection of Information Assets
Failing to conduct a thorough risk assessment before selecting controls, leading to misaligned security investments.
Protection of Information Assets
Implementing controls without proper testing and validation, resulting in ineffective or misconfigured safeguards.
Protection of Information Assets
Treating security controls as a one-time implementation rather than a continuous process requiring ongoing monitoring and adaptation.
Protection of Information Assets
Framework for managing digital identities and access rights.
Protection of Information Assets
Verifying a user's claimed identity.
Protection of Information Assets
Determining what an authenticated user can do.
Protection of Information Assets
Access control model based on user roles.
Protection of Information Assets
Transforming data into ciphertext to protect it.
Protection of Information Assets
Uses one key for both encryption and decryption.
Protection of Information Assets
Uses a public/private key pair for encryption/decryption.
Protection of Information Assets
Secure handling of cryptographic keys.
Protection of Information Assets
For Access Control Models, remember 'DAMN R': Discretionary, Administrative, Mandatory, Network, Role-Based. (Focus on DAC, MAC, RBAC for the exam.)
Protection of Information Assets
The CISA exam frequently tests the distinction between authentication (who you are) and authorization (what you can do). Also, understand the benefits and drawbacks of symmetric versus asymmetric encryption, and the critical role of key management.
Protection of Information Assets
Confusing authentication with authorization; they are distinct steps in the access process.
Protection of Information Assets
Underestimating the importance of key management in an encryption scheme; weak key management renders strong encryption useless.
Protection of Information Assets
Failing to apply the principle of least privilege, granting users more access than necessary for their job functions.
Protection of Information Assets
Network security system monitoring and controlling traffic.
Protection of Information Assets
Detects/prevents malicious network activity.
Protection of Information Assets
Protects individual devices like computers and mobile phones.
Protection of Information Assets
Documented procedure for handling security breaches.
Protection of Information Assets
Subnetwork exposing external-facing services securely.
Protection of Information Assets
Tools preventing sensitive data from leaving the network.
Protection of Information Assets
P-I-C-E-R-L: **P**repare, **I**dentify, **C**ontain, **E**radicate, **R**ecover, **L**earn. It's like a recipe for fixing a security mess!
Protection of Information Assets
The exam often tests your understanding of the *phases* of incident response and the auditor's role in *evaluating* the effectiveness of each phase. Keywords to spot include 'preparation,' 'identification,' 'containment,' 'eradication,' 'recovery,' and 'lessons learned.' Memorize the order and what happens in each phase.
Protection of Information Assets
Confusing IDS (detection) with IPS (prevention) – remember IPS actively blocks.
Protection of Information Assets
Assuming a documented incident response plan is automatically effective without testing.
Protection of Information Assets
Overlooking the importance of patch management for endpoint security, often seen as 'basic' but critical.
Protection of Information Assets