IS audit standards, risk based audit planning, and audit process concepts tested on the CISA exam.
42 cards · basic cards · AI-written, checked twice. Edit anything.
- What is the primary purpose of a CISA (Certified Information Systems Auditor)?
- To provide audit assurance and advice on information and related technology to assess risk management, controls, and governance processes.
- Define risk-based auditing.
- An audit approach that prioritizes testing resources on areas with the highest risk to the organization.
- What are the three main phases of the audit process?
- Planning, fieldwork (execution), and reporting.
- What is COBIT?
- A framework for IT governance and management of enterprise IT, developed by ISACA to align IT with business objectives.
- Define control objectives.
- High-level statements describing the desired result or purpose of implementing controls over IT processes.
- What is the difference between a control objective and a control activity?
- A control objective is the desired outcome; a control activity is the specific action taken to achieve that objective.
- What is materiality in auditing?
- The threshold at which misstatements or deficiencies would influence the economic decisions of users relying on the audit results.
- Name three types of audit evidence.
- Physical, documentary, testimonial, analytical, and electronic (any three).
- What is an audit trail?
- A record of system activities and transactions that allows reconstruction of events and accountability for data changes.
- Define IT governance.
- The structure, processes, and mechanisms by which IT is directed and controlled to support the organization's objectives.
- What is change management in the context of IT auditing?
- The formal process for controlling and documenting modifications to IT systems, infrastructure, and configurations.
- What is configuration management?
- The process of identifying, documenting, and controlling IT infrastructure components and their relationships.
- Define risk appetite.
- The amount and type of risk an organization is willing to accept in pursuit of its strategic objectives.
- What are Key Risk Indicators (KRIs)?
- Metrics that provide early warning signals of increasing risk exposure in specific areas.
- What is the PDCA cycle?
- Plan-Do-Check-Act, a cyclical process for continuous improvement of processes and controls.