FlashKeepers

CISM/CISA · CISA

CISA Information Systems Auditing Process

IS audit standards, risk based audit planning, and audit process concepts tested on the CISA exam.

42 cards · basic cards · AI-written, checked twice. Edit anything.

Study this set free Look inside first Get FlashKeepers for iPhone
What is the primary purpose of a CISA (Certified Information Systems Auditor)?
To provide audit assurance and advice on information and related technology to assess risk management, controls, and governance processes.
Define risk-based auditing.
An audit approach that prioritizes testing resources on areas with the highest risk to the organization.
What are the three main phases of the audit process?
Planning, fieldwork (execution), and reporting.
What is COBIT?
A framework for IT governance and management of enterprise IT, developed by ISACA to align IT with business objectives.
Define control objectives.
High-level statements describing the desired result or purpose of implementing controls over IT processes.
What is the difference between a control objective and a control activity?
A control objective is the desired outcome; a control activity is the specific action taken to achieve that objective.
What is materiality in auditing?
The threshold at which misstatements or deficiencies would influence the economic decisions of users relying on the audit results.
Name three types of audit evidence.
Physical, documentary, testimonial, analytical, and electronic (any three).
What is an audit trail?
A record of system activities and transactions that allows reconstruction of events and accountability for data changes.
Define IT governance.
The structure, processes, and mechanisms by which IT is directed and controlled to support the organization's objectives.
What is change management in the context of IT auditing?
The formal process for controlling and documenting modifications to IT systems, infrastructure, and configurations.
What is configuration management?
The process of identifying, documenting, and controlling IT infrastructure components and their relationships.
Define risk appetite.
The amount and type of risk an organization is willing to accept in pursuit of its strategic objectives.
What are Key Risk Indicators (KRIs)?
Metrics that provide early warning signals of increasing risk exposure in specific areas.
What is the PDCA cycle?
Plan-Do-Check-Act, a cyclical process for continuous improvement of processes and controls.

27 more cards in the app