All certifications / CISA / Cheat sheet
CISA 2024 job practice cheat sheet
Domain 1: Information system auditing process (18%)
Exam tips
- When a question involves an independence problem, the answer is almost always to disclose it to audit management or the audit committee, not to carry on quietly or narrow the scope without telling anyone.
- Control self-assessment does not replace audit. If an answer suggests CSA removes the need for independent testing, it is wrong; CSA supplements audit and improves ownership.
- If asked what the auditor should do first when planning, choose understanding the business and assessing risk. Choosing tests, samples or tools comes later.
- Weak general controls undermine application controls. If a question asks what to test before relying on automated application controls, IT general controls such as change management come first.
- If an auditee refuses access or restricts scope, the right answer is to document it and escalate through audit management, not to drop the objective or proceed as if nothing happened.
- Match the method to the question: attribute sampling for how often a control fails, variable or monetary unit sampling for how much money is wrong, discovery sampling for proving a rare event exists.
- When ranking evidence, prefer independent over internal, auditor-obtained over auditee-provided, and documentary or reperformed over oral statements.
- Before trusting any analytics result, verify the completeness and accuracy of the extracted data. And remember that continuous monitoring belongs to management, while continuous auditing belongs to audit.
- Auditors report and verify; they do not fix. Any option where the auditor implements the corrective action or quietly drops a supported finding is wrong.
Key terms
- ITAF
- ISACA's IT Audit Framework: mandatory standards, supporting guidelines, and tools and techniques for IS audit and assurance work.
- Audit charter
- A board- or audit committee-approved document that sets out the audit function's purpose, authority, responsibility and access rights.
- Organizational independence
- A reporting line for the audit function, usually to the audit committee, that lets it work without interference from the areas it audits.
- Independence in appearance
- The absence of circumstances that would lead a reasonable third party to doubt the auditor's objectivity.
- Due professional care
- Applying the skill and diligence that a prudent, competent auditor would use in the same circumstances.
- Self-review threat
- The risk that an auditor will not critically evaluate work they performed or designed themselves.
- Code of Professional Ethics
- ISACA's set of conduct principles that members and certification holders agree to follow, enforced through disciplinary procedures.
- Integrated audit
- An audit that combines financial, operational and IS audit work to evaluate all the controls over a process or system together.
- Control self-assessment (CSA)
- A technique in which process owners and staff evaluate their own controls, usually in facilitated workshops.
- Forensic audit
- An engagement to collect and analyze evidence about suspected fraud or crime for possible legal or disciplinary use.
- Compliance audit
- An audit that tests adherence to specific laws, regulations, contracts or internal policies.
- Operational audit
- An audit that evaluates the efficiency, effectiveness and economy of a process or function.
- Chain of custody
- A documented record of who collected, handled and stored evidence, and when, showing it was not altered.
- Reasonable assurance
- A high but not absolute level of assurance, which is the level an audit opinion provides.
- Audit universe
- The complete list of auditable areas in the organization, used as the starting point for risk-based planning.
- Inherent risk
- The risk of an error or loss before considering any controls.
- Control risk
- The risk that an error will not be prevented or detected in time by the organization's controls.
- Detection risk
- The risk that the auditor's procedures fail to detect a material error; the only part of audit risk the auditor controls.
- Materiality
- The significance of a weakness or error, judged by its potential effect on decisions or objectives, not only its monetary value.
- Engagement scope
- The boundaries of a specific audit: the systems, processes, locations and time period included.
- Preventive control
- A control designed to stop an error or irregularity from occurring.
- Detective control
- A control that identifies errors or irregularities after they have occurred.
- Corrective control
- A control that fixes a problem and limits its impact once it has been detected.
- Compensating control
- An alternative control that reduces risk to an acceptable level when the primary control cannot be implemented.
- IT general control (ITGC)
- A control over the IT environment, such as access or change management, that supports all applications running in it.
- Application control
- A control inside a specific application that ensures complete, accurate and authorized input, processing and output.
- Operating effectiveness
- Whether a control actually functioned as designed, consistently, throughout the period under review.
- Audit program
- A step-by-step list of audit procedures designed to meet the objectives of a specific engagement.
- Workpapers
- The documented record of audit planning, procedures, evidence and conclusions, reviewed by a senior auditor.
- Engagement letter
- A document that confirms the scope, objectives, timing, responsibilities and access for an audit.
- Scope limitation
- A restriction on the auditor's access or procedures that prevents gathering sufficient evidence.
- Fieldwork
- The phase of an audit in which tests are performed and evidence is gathered.
- Guest auditor
- A subject matter expert from another part of the organization or outside who joins an engagement to supply missing skills.
- Compliance test
- A test of whether a control operates as designed, such as checking approvals on a sample of changes.
- Substantive test
- A test of the data or transactions themselves to detect errors or misstatement.
- Attribute sampling
- A method that estimates the rate at which a characteristic, such as a control failure, occurs in a population.
- Variable sampling
- A method that estimates a monetary amount or other quantity in a population, used for substantive testing.
- Discovery sampling
- A form of attribute sampling designed to find at least one instance of a rare event, such as fraud.
- Tolerable error rate
- The maximum rate of deviation the auditor is willing to accept and still rely on the control.
- Stratification
- Dividing a population into subgroups with similar characteristics so each can be sampled appropriately.
- Sufficient evidence
- Enough evidence, in quantity and coverage, to support the audit conclusion.
- Reliable evidence
- Evidence whose source, method and conditions of production make it trustworthy.
- Relevant evidence
- Evidence that logically relates to and addresses the specific audit objective.
- Reperformance
- The auditor independently executing a control or calculation to confirm it produces the correct result.
- Corroboration
- Obtaining additional evidence to confirm information gathered through inquiry or other weaker sources.
- Walkthrough
- Tracing a single transaction through a process to confirm the auditor's understanding of controls.
- Confirmation
- Evidence obtained directly from an independent third party, such as a bank or vendor, in response to the auditor's request.
- CAAT
- Computer-assisted audit technique: using software to extract and analyze data or test system logic as part of an audit.
- Parallel simulation
- Reprocessing production data with auditor-controlled software and comparing the results with the production output.
- Test data
- Dummy transactions, valid and invalid, run through a program to check that it processes and rejects them correctly.
- Integrated test facility (ITF)
- A technique that creates fictitious entities in a live system so auditor test transactions are processed alongside real ones.
- Embedded audit module
- Code inside an application that selects transactions meeting audit criteria as they are processed.
- Continuous auditing
- Audit testing performed automatically and frequently, close to when transactions occur.
- Continuous monitoring
- Management's ongoing, automated oversight of controls and key indicators.
- Condition
- The part of a finding that states what the auditor actually observed.
- Criteria
- The standard, policy or expectation that the condition is measured against.
- Cause
- The underlying reason the condition differs from the criteria, which a lasting fix must address.
- Effect
- The actual or potential impact or risk that results from the condition.
- Exit meeting
- A meeting at the end of fieldwork where findings are discussed with management before the report is finalized.
- Follow-up
- Audit procedures that verify whether agreed corrective actions were implemented and effective.
- External quality assessment
- An independent review of the audit function's conformance with standards and its effectiveness.
Domain 2: Governance and management of IT (18%)
Exam tips
- The first audit question about a new law is whether management has identified and assessed the requirements. Controls and tools come after that assessment.
- Governance is the board's job; management executes. If an answer places ultimate accountability with the CIO or IT department, look for the board instead.
- Policies are approved by senior management and state intent; they should not contain technical detail. If a question asks what the auditor reviews first to understand management's intent, pick the policy.
- Risk acceptance belongs to a business owner with authority, within the risk appetite. Auditors identify and report risks; they never accept them, and transferring risk never transfers accountability.
- Security and privacy overlap but differ. A question about using data for a new purpose, collecting too much or keeping it too long is about privacy principles, not encryption.
- The owner decides and is accountable; the custodian implements. When asked who classifies data or approves access, choose the business owner, not IT or security.
- The classic IT SoD conflict is the same person developing and moving code to production. If full separation is impossible, look for a compensating detective control performed by someone independent.
- Type 1 means design only at one point; Type 2 adds operating effectiveness over time. An auditor relying on a vendor's controls normally wants Type 2, and must still check scope, exceptions and complementary user entity controls.
- Look for measures that show value and outcomes, not just activity. A balanced scorecard that links IT to business goals is usually the best answer for showing IT's contribution.
Key terms
- Regulatory compliance
- Meeting the requirements imposed by laws and regulations that apply to the organization.
- Compliance register
- A maintained list of applicable legal, regulatory and contractual requirements with owners and status.
- Gap assessment
- A comparison of current controls and practices against a set of requirements to identify shortfalls.
- Breach notification
- A legal requirement to inform regulators or affected people when certain data is compromised.
- Industry standard
- A requirement set developed by an industry body, such as for card payments, which may become binding through contracts.
- Data residency
- A requirement that certain data be stored or processed within a specific country or region.
- IT governance
- The leadership, structures and processes that ensure IT supports the organization's strategy and objectives.
- IT steering committee
- A management committee of business and IT leaders that prioritizes, approves and monitors IT investments.
- IT strategy committee
- A board-level committee that advises the board on the strategic direction of IT.
- Business alignment
- The degree to which IT plans and investments support the organization's strategic goals.
- IT strategic plan
- A multi-year plan describing how IT will support business goals, including priorities, investments and measures.
- Shadow IT
- Technology acquired or used by business units without the knowledge or approval of IT governance.
- RACI chart
- A matrix showing who is responsible, accountable, consulted and informed for each activity or decision.
- Policy
- A high-level, management-approved statement of intent and direction.
- Standard
- A mandatory, specific requirement that supports a policy.
- Procedure
- Detailed, step-by-step instructions to perform a task.
- Guideline
- Recommended but optional advice on how to meet a policy or standard.
- Baseline
- A minimum required configuration or security level for a specific platform or system.
- COBIT
- ISACA's framework for governance and management of enterprise information and technology.
- Policy exception
- A formally requested, risk-assessed and approved deviation from a policy or standard, usually time-limited.
- Enterprise architecture
- A structured description of business processes, information, applications and technology and how they should evolve.
- Enterprise risk management (ERM)
- The organization-wide process for identifying, assessing, responding to, monitoring and reporting risks to objectives.
- Risk appetite
- The amount and type of risk an organization is willing to pursue or retain to achieve its objectives.
- Risk tolerance
- The acceptable level of variation around a specific objective or risk appetite.
- Residual risk
- The risk remaining after controls and other responses are applied.
- Risk owner
- The person accountable for managing a particular risk and deciding on its response.
- Risk transfer
- Shifting some of the financial impact of a risk to another party, such as an insurer, while keeping accountability.
- Purpose limitation
- The principle that personal data is used only for the specific purposes for which it was collected.
- Data minimization
- Collecting and keeping only the personal data that is necessary for the stated purpose.
- Storage limitation
- Keeping personal data in identifiable form no longer than necessary for its purpose.
- Privacy impact assessment (PIA)
- An evaluation of how a new system or change affects personal data and privacy risk, done before it is implemented.
- Privacy by design
- Building privacy protections into systems and processes from the start, with protective settings as the default.
- Pseudonymization
- Replacing direct identifiers with tokens so data can be re-linked only using separately protected information.
- Data protection officer (DPO)
- A person responsible for overseeing an organization's privacy compliance and advising on data protection obligations.
- Data owner
- The business manager accountable for a data set, who decides its classification and approves access.
- Data custodian
- The party, often IT, that implements and maintains controls over data on the owner's behalf.
- Data steward
- A person responsible for the quality, definitions and proper use of data day to day.
- Data classification
- Assigning data to sensitivity levels that determine how it must be handled and protected.
- Data inventory
- A catalog of the organization's data sets, where they reside, their owners and their classification.
- Data lineage
- A record of where data originated and how it has been moved and transformed.
- Data loss prevention (DLP)
- Tools and processes that detect and block unauthorized movement of sensitive data based on its classification.
- Segregation of duties
- Dividing incompatible duties among different people so that no single person can commit and conceal errors or fraud.
- SoD matrix
- A table of roles or permissions that marks which combinations are incompatible, used to detect conflicts.
- Compensating control
- An alternative control that reduces risk when the ideal control, such as full segregation of duties, cannot be applied.
- Job rotation
- Periodically moving staff between roles, which reduces dependence on individuals and can reveal irregularities.
- Mandatory vacation
- Requiring staff in sensitive roles to take consecutive leave so others perform their duties and irregularities surface.
- Portfolio management
- Managing a set of IT investments together to maximize value and alignment within available resources.
- Chargeback
- A cost allocation model that bills business units for the IT services they consume.
- Right-to-audit clause
- A contract term allowing the customer, or its auditors, to audit the vendor's controls.
- Service level agreement (SLA)
- A contract section defining measurable service targets, how they are reported and the remedies if they are missed.
- SOC 1
- An independent report on a service organization's controls relevant to customers' internal control over financial reporting.
- SOC 2 Type 2
- An independent report on a service organization's controls over the trust services criteria, including testing of operating effectiveness over a period.
- Complementary user entity controls
- Controls that the customer must perform for the service organization's controls to be effective.
- Source code escrow
- An arrangement where a third party holds a vendor's source code, released to the customer if the vendor fails.
- Carve-out method
- A SOC reporting approach that excludes a subservice organization's controls from the report's scope.
- Key performance indicator (KPI)
- A measure of how well a process or activity is achieving its objective.
- Key risk indicator (KRI)
- A metric that signals increasing exposure to a particular risk.
- Balanced scorecard
- A performance tool that measures IT across business contribution, user orientation, operational excellence and future orientation perspectives.
- Operational level agreement (OLA)
- An agreement between internal teams that defines the support needed to meet an external service level agreement.
- Capability level
- A rating of how well a process is performed and managed, from incomplete to optimized.
- Quality assurance
- Activities that define and check processes to prevent defects, as opposed to inspecting outputs.
- Maturity model
- A staged model describing how processes evolve from ad hoc to optimized, used to assess and plan improvement.
Domain 3: Information systems acquisition, development and implementation (12%)
Exam tips
- Know the formulas: CV = EV - AC, SV = EV - PV, CPI = EV / AC, SPI = EV / PV. Negative variances or indexes below 1 mean trouble.
- When a project's costs rise or benefits fall, the best answer is usually to re-evaluate the business case, not to continue because of money already spent.
- Agile and DevOps do not mean no controls. Look for controls in different places: backlog acceptance criteria, definition of done, automated tests and pipeline approval gates.
- Match the control to the error: validity or range checks for bad individual values, check digits for transcription errors, record counts and hash totals for missing or altered batch items, reconciliations for completeness of output.
- UAT sign-off belongs to the business users and system owner, not IT. And production data used in testing should be masked to protect privacy.
- Parallel is lowest risk and highest cost; direct cutover is highest risk and lowest cost. Phased and pilot sit in between. Always confirm the deployed version is the one that was tested.
- Matching record counts alone do not prove a conversion was accurate. The strongest evidence is reconciliation of counts, control totals and hash totals plus a detailed sample, signed off by the data owner, with the old data retained until verification is complete.
- The PIR happens after the system has run long enough to measure results, not right after go-live and not before. Its reference point is the approved business case, and benefits belong to a business owner, not the project manager.
Key terms
- Project sponsor
- The senior business leader who owns the business case, funds the project and is accountable for its benefits.
- Project steering committee
- A group of senior stakeholders that directs the project and approves major changes to scope, budget and schedule.
- Earned value
- The budgeted cost of the work actually completed at a point in time.
- Cost performance index (CPI)
- Earned value divided by actual cost; below 1 means the project is over budget.
- Critical path
- The longest sequence of dependent tasks, which determines the shortest possible project duration.
- Work breakdown structure (WBS)
- A hierarchical decomposition of project deliverables into manageable work packages.
- Scope creep
- Uncontrolled growth in project scope without matching changes in budget, time or approval.
- Business case
- A document that justifies an investment by comparing options, costs, benefits and risks.
- Feasibility study
- An analysis of whether a proposed solution is technically, economically, operationally, legally and schedule-wise practical.
- Total cost of ownership (TCO)
- All costs of a solution over its life, including acquisition, operation, support and retirement.
- Net present value (NPV)
- The value today of future cash inflows minus outflows, discounted to account for the time value of money.
- Payback period
- The time it takes for cumulative benefits to equal the initial investment.
- Request for proposal (RFP)
- A formal document inviting vendors to propose solutions against stated requirements and evaluation criteria.
- Sunk cost
- Money already spent that cannot be recovered and should not drive future decisions.
- Waterfall (SDLC)
- A sequential development approach where each phase is completed and signed off before the next begins.
- Product backlog
- A prioritized list of features and requirements, usually written as user stories, used in agile development.
- Definition of done
- The agreed criteria, such as passing tests and review, that a work item must meet before it is considered complete.
- DevOps
- Practices that combine development and operations with automation to deliver changes quickly and reliably.
- CI/CD pipeline
- An automated sequence that builds, tests and releases code changes, often with gates for review and approval.
- Prototyping
- Building an early working model of a system to refine requirements with users.
- Rapid application development (RAD)
- A method that uses prototypes, reusable components and timeboxing to deliver systems quickly.
- Validity check
- An edit check that accepts only values that are permitted for a field, such as real dates or valid codes.
- Check digit
- A calculated digit appended to a number that detects transcription errors when the number is entered.
- Hash total
- A total of a non-financial field, such as account numbers, used to detect changes or missing items in a batch.
- Control total
- A total of a meaningful amount field, such as invoice value, compared before and after processing.
- Run-to-run totals
- Control totals carried from one processing step to the next to confirm nothing was lost or added.
- Suspense file
- A holding area for rejected transactions until they are corrected and resubmitted by authorized staff.
- Audit trail
- A chronological record of system activity showing who did what and when, supporting detection and investigation.
- Unit testing
- Testing individual program modules in isolation, usually by developers.
- Integration testing
- Testing that modules and interfaces work together and pass data correctly.
- User acceptance testing (UAT)
- Testing by business users to confirm the system meets their requirements before go-live.
- Regression testing
- Rerunning previous tests after a change to confirm existing functions still work.
- Black-box testing
- Testing functionality by checking outputs for given inputs without examining internal code.
- Stress testing
- Testing system behavior at and beyond expected peak loads to find breaking points.
- Data masking
- Replacing sensitive values in test data with realistic but fictitious values to protect privacy.
- Configuration management
- Identifying, recording and controlling the approved configuration of system components and verifying it matches what is running.
- Configuration management database (CMDB)
- A repository that records configuration items, their attributes and relationships.
- Release management
- The process of planning, packaging, approving and deploying tested changes into production.
- Parallel changeover
- Running the old and new systems at the same time and comparing results before switching fully.
- Pilot changeover
- Implementing the new system in one location or group first before rolling it out more widely.
- Direct cutover
- Switching from the old system to the new one at a single point in time with no parallel running.
- Rollback plan
- A prepared procedure to return to the previous state if a release fails.
- Data conversion
- Transforming and moving data from an old system's format into a new system's format.
- Data mapping
- Defining which field in the source system corresponds to which field in the target system, with any transformation rules.
- Parallel run
- Operating the old and new systems at the same time and comparing their results before relying on the new one.
- Infrastructure as code (IaC)
- Defining servers, networks and cloud resources in version-controlled files that tools use to build environments automatically.
- Shared responsibility model
- The division of security duties between a cloud provider and its customer, which varies by service model.
- Post-implementation review (PIR)
- A review after a system has operated for a while to assess whether it met its objectives, delivers expected benefits and has effective controls.
- Benefits realization
- Planning, tracking and confirming that the benefits promised in the business case are actually achieved.
- Benefit owner
- The business manager accountable for delivering a specific benefit after the project closes.
- Lessons learned
- Documented insights from a project about what worked and what did not, intended to improve future projects.
- Baseline
- The measured starting value of a metric, used to show how much a project changed it.
Domain 4: Information systems operations and business resilience (26%)
Exam tips
- To test inventory completeness, trace from the real world (discovery scans, purchase records) to the register. Tracing from the register to the asset only proves the recorded items exist.
- For interfaces, the best completeness control is reconciliation of counts and totals between sending and receiving systems, plus sequence numbers for gaps and duplicates. Encryption protects confidentiality but does not prove completeness.
- For shadow IT, the best first step is discovery and risk assessment, not blocking everything. For EUC, the key risks are missing change control, testing, access control and backup on tools that feed important decisions.
- Capacity management is proactive: it uses utilization trends and business forecasts to act before resources run out. Answers that wait for a failure or only react to user complaints are wrong.
- Incident management restores service fast, even with a workaround. Problem management finds and fixes the root cause through change management. Repeated identical incidents point to missing problem management.
- To find unauthorized changes, sample from what actually changed in production (system logs, version control, deployment records) and trace back to approvals. Sampling only from approved tickets cannot reveal changes that never had one.
- The best evidence of SLA performance is reliable, independent measurement compared with agreed targets. For logs, the key concerns are completeness, protection from alteration, adequate retention and evidence of actual review.
- DBAs can bypass application controls. The best answers involve named accounts, logging DBA activity to a location they cannot modify, and independent review of those logs, plus approval and logging of any direct data fixes.
- RPO is about data loss and drives backup or replication frequency; RTO is about time to restore and drives the recovery site choice. The RTO must be shorter than the MTD, and the BIA comes before choosing strategies or sites.
- A successful backup job does not prove recoverability. Periodic restore tests are the best evidence that backups work, and at least one copy should be offsite and offline or immutable to survive ransomware.
- The BIA comes first, then strategy, plan, testing and maintenance. After a failed test, update the plan and retest; after major changes, update the plan. A parallel test proves recovery without stopping production.
Key terms
- IT asset management (ITAM)
- Tracking and controlling IT assets from request and procurement through use to retirement and disposal.
- Configuration management database (CMDB)
- A repository of IT components and their relationships, used to support change, incident and asset management.
- Software asset management (SAM)
- Managing software installations and use against purchased licenses to stay compliant and avoid waste.
- End of life (EOL)
- The point after which a vendor no longer supports a product with fixes or security updates.
- Automated discovery
- Tools that scan networks and systems to find devices and software, including ones missing from the inventory.
- Cryptographic erase
- Sanitizing encrypted media by securely destroying the encryption key so the stored data cannot be read.
- Media sanitization
- Removing data from storage media so it cannot be recovered, using methods suited to the media and sensitivity.
- Job scheduler
- Software that runs batch jobs automatically in a defined order and time, handling dependencies between them.
- Batch processing
- Processing groups of transactions together at scheduled times rather than one at a time as they occur.
- System interface
- A connection that transfers data between two applications, in batches or in real time.
- Application programming interface (API)
- A defined way for one program to request data or services from another.
- Sequence number
- A number assigned to each transmission or record so gaps and duplicates can be detected.
- Robotic process automation (RPA)
- Software bots that perform repetitive tasks by interacting with applications the way a user would.
- Rerun log
- A record of jobs that were restarted or run again, reviewed to detect duplicate or unauthorized processing.
- End-user computing (EUC)
- Applications such as spreadsheets, desktop databases and low-code tools built or managed by business users rather than IT.
- Shadow IT
- Technology, especially cloud services, acquired or used without the knowledge or approval of the IT function.
- EUC inventory
- A register of end-user tools that support important processes, with owners and risk ratings.
- Cloud access security broker (CASB)
- A tool that discovers cloud service use and applies security policies between users and cloud providers.
- Proportionate control
- A control whose strength matches the risk of the process or tool it protects.
- Key person dependency
- Reliance on one individual who alone understands or can maintain a process or tool.
- Availability
- The proportion of agreed service time during which a system or service is able to perform its function.
- Capacity management
- Ensuring IT resources meet current and forecast demand at acceptable cost and performance.
- Mean time between failures (MTBF)
- The average operating time between failures of a component, a measure of reliability.
- Mean time to repair (MTTR)
- The average time taken to restore a component or service after a failure, a measure of maintainability.
- Resilience
- The ability of a service to keep operating, possibly at a reduced level, when some components fail.
- Capacity plan
- A document that forecasts resource demand and sets out thresholds and planned actions to meet it.
- Auto-scaling
- Automatically adding or removing cloud resources in response to demand, within defined limits.
- Incident
- An unplanned interruption or reduction in the quality of an IT service.
- Problem
- The unknown underlying cause of one or more incidents.
- Root cause analysis
- A structured investigation, using techniques such as the five whys, to find the fundamental cause of a problem.
- Known error
- A problem whose root cause is identified and documented, often with a workaround, but not yet permanently fixed.
- Known error database (KEDB)
- A repository of known errors and workarounds that helps the service desk resolve incidents faster.
- Workaround
- A temporary way to reduce or remove the impact of an incident without fixing its root cause.
- Escalation
- Passing an incident to more specialized teams (functional) or to management (hierarchical) when needed.
- Change advisory board (CAB)
- A group that reviews and approves or rejects significant changes to production systems.
- Emergency change
- An urgent change that follows an expedited path but must still be logged and reviewed and approved afterward.
- Standard change
- A low-risk, pre-approved, repeatable change that follows a defined procedure.
- Configuration item (CI)
- Any component that is managed and recorded, such as a server, application version or network device.
- Configuration drift
- Divergence of a system's actual settings from its approved configuration baseline.
- Release management
- Planning, packaging and deploying approved changes to production in a controlled way.
- Patch management
- Identifying, testing, prioritizing, deploying and verifying vendor updates that fix vulnerabilities and defects.
- Log retention
- The period for which logs must be kept, set by policy, contract or regulation.
- Time synchronization
- Keeping system clocks aligned, usually with NTP, so events from different systems can be correlated.
- Centralized logging
- Forwarding logs to a separate, protected store so they cannot be altered by the source system's administrators.
- Service level agreement (SLA)
- An agreement between an IT service provider and its customer that sets measurable service targets.
- Operational level agreement (OLA)
- An internal agreement between IT teams that supports delivery of an SLA.
- Underpinning contract
- A contract with an external supplier that supports the service targets in an SLA.
- Service catalog
- A list of the IT services offered, with their descriptions, owners and service levels.
- Database management system (DBMS)
- Software that stores and manages data, controlling access, integrity, concurrency and recovery.
- Referential integrity
- A rule that every foreign key value must match an existing primary key in the related table.
- Entity integrity
- A rule that every row has a unique, non-null primary key.
- Normalization
- Organizing tables so each fact is stored once, reducing redundancy and update anomalies.
- ACID
- Atomicity, consistency, isolation and durability: the properties that make database transactions reliable.
- Database activity monitoring (DAM)
- Tools that record and analyze database activity, alerting on unusual or unauthorized actions.
- Data fix
- A direct change to production data outside the normal application, which should be approved, logged and reviewed.
- Business impact analysis (BIA)
- An analysis that identifies critical processes, their dependencies and the impact of disruption over time.
- Maximum tolerable downtime (MTD)
- The longest a process can be unavailable before the impact becomes unacceptable to the organization.
- Recovery time objective (RTO)
- The target time within which a system or process must be restored after a disruption.
- Recovery point objective (RPO)
- The maximum acceptable amount of data loss, measured as time before the disruption.
- Service delivery objective (SDO)
- The level of service that must be achieved during the recovery period.
- Criticality
- The relative importance of a process or system, based on the impact of its loss.
- Dependency
- A resource, such as a system, supplier or facility, that a process needs in order to operate.
- Single point of failure
- A component whose failure alone stops the whole service.
- Redundant array of independent disks (RAID)
- A method of combining disks for performance, redundancy or both, with levels such as 1, 5, 6 and 10.
- Incremental backup
- A backup of changes since the last backup of any type; fast to create but slower to restore.
- Differential backup
- A backup of all changes since the last full backup; a restore needs only the full backup and the latest differential.
- Immutable backup
- A backup copy that cannot be modified or deleted for a defined period, protecting it from ransomware.
- Fault tolerance
- The ability of a system to continue operating without interruption when a component fails.
- Synchronous replication
- Replication in which writes are confirmed only after both sites store them, giving near-zero data loss.
- Business continuity plan (BCP)
- A plan for keeping critical business processes running during and after a disruption.
- Disaster recovery plan (DRP)
- The part of continuity planning that restores IT systems, data and infrastructure.
- Hot site
- A fully equipped alternate site with current data that can take over within hours.
- Warm site
- An alternate site with some equipment and connectivity that needs configuration and data restoration before use.
- Cold site
- An alternate site providing only space, power and environmental controls, with equipment to be installed.
- Tabletop exercise
- A discussion-based test in which the team walks through a scenario to check roles and procedures.
- Parallel test
- A test that brings up recovery systems and processes data at the alternate site without stopping production.
- Full interruption test
- A test that actually shuts down primary operations and runs from the recovery site.
Domain 5: Protection of information assets (26%)
Exam tips
- Policies, standards and procedures are mandatory; guidelines are advisory. Owners decide protection needs and custodians implement them. Exceptions must be formal, approved, risk-assessed and time-limited.
- A camera or sign-in sheet detects or deters; a mantrap prevents tailgating. For staffed data centers, pre-action sprinklers balance life safety with water damage risk, and a UPS covers short outages while generators cover long ones.
- Owners review access; administrators implement it. For leavers, the best control links HR terminations to automatic account removal, supported by periodic owner reviews. Two of the same factor type is not MFA.
- IDS detects and alerts; IPS sits inline and blocks. Firewall rule sets should deny by default, and a broad allow rule near the top defeats everything below it. Segmentation limits how far a compromise spreads.
- Encryption is only as good as its key management; a key stored next to the data it protects is a common finding. Hashing proves integrity but is not encryption, and DLP depends on data classification.
- Sign with your own private key; others verify with your public key. Encrypt for confidentiality with the recipient's public key. Symmetric keys cannot give non-repudiation because both sides hold them.
- In the cloud, the customer always keeps accountability for its data, identities and configuration. Most cloud breaches come from customer misconfiguration, not provider failure, and a provider's SOC report assumes the customer performs its own complementary controls.
- Measure awareness by behavior change, such as phishing simulation click and report trends, rather than training attendance. For payment fraud, independent call-back verification using known contact details is a strong process control.
- A vulnerability scan identifies weaknesses; a penetration test exploits them to prove impact. No penetration test should start without written authorization and agreed rules of engagement, and findings mean little without tracked remediation.
- A SIEM with missing log sources or unreviewed alerts gives false comfort. Coverage checked against the asset inventory, continuous tuning and documented evidence that alerts are investigated are what make monitoring effective.
- Collect evidence in order of volatility, work only on hash-verified copies and keep chain of custody. Before restoring after ransomware, make sure the attacker's access is removed and the backups are clean.
Key terms
- Information security policy
- A high-level, management-approved statement of security objectives, scope, roles and commitment.
- Standard
- A mandatory, specific requirement that implements a policy, such as minimum encryption strength.
- Guideline
- Recommended, non-mandatory advice on good practice.
- Security baseline
- The minimum secure configuration required for a type of system, used to harden and assess it.
- Information security management system (ISMS)
- A management process, defined in ISO/IEC 27001, for managing information security risks and improving controls.
- Policy exception
- A formally approved, time-limited deviation from a policy or standard, with assessed risk and compensating controls.
- Data owner
- The business manager accountable for a data set, who decides its classification and who may access it.
- Mantrap (access control vestibule)
- A space with two interlocking doors that admits one authorized person at a time.
- Tailgating
- Following an authorized person through a secured door without authorization.
- Uninterruptible power supply (UPS)
- A battery-based device that supplies and conditions power during short outages and fluctuations.
- Pre-action sprinkler
- A sprinkler system that fills its pipes with water only after detection, then discharges when a head opens.
- Dry-pipe sprinkler
- A sprinkler system whose pipes hold pressurized air until a head opens, used where pipes could freeze.
- Clean agent suppression
- A gas-based fire suppression system that leaves no residue and does not damage electronic equipment.
- Defense in depth
- Layering several controls so that the failure of one does not expose the protected asset.
- Least privilege
- Granting users only the access they need to perform their job, and no more.
- Multifactor authentication (MFA)
- Authentication that requires two or more different factor types, such as knowledge, possession and inherence.
- Role-based access control (RBAC)
- An authorization model in which permissions are assigned to roles and users receive roles.
- Privilege creep
- The gradual accumulation of access rights as users change roles without losing old access.
- Access recertification
- A periodic review in which owners confirm or remove each user's access.
- Privileged access management (PAM)
- Tools and processes that control, monitor and limit administrator and other high-risk accounts.
- Single sign-on (SSO)
- A system that lets users authenticate once and access multiple applications, relying on a trusted identity provider.
- Stateful inspection
- Firewall filtering that tracks the state of connections and allows return traffic for established sessions.
- Network segmentation
- Dividing a network into zones with controlled traffic between them to limit the spread of compromise.
- Demilitarized zone (DMZ)
- A network segment that hosts internet-facing services, separated from both the internet and the internal network.
- Intrusion prevention system (IPS)
- An inline system that detects and blocks malicious traffic, unlike an IDS, which only alerts.
- Endpoint detection and response (EDR)
- Endpoint software that records behavior, detects threats and lets analysts investigate and contain devices.
- Zero trust
- A security model that verifies every access request based on identity and context rather than network location.
- Shadowed rule
- A firewall rule that never takes effect because an earlier rule matches the same traffic.
- Data loss prevention (DLP)
- Tools and processes that detect sensitive data and monitor or block its unauthorized movement.
- Symmetric encryption
- Encryption that uses the same secret key to encrypt and decrypt, fast enough for bulk data.
- Asymmetric encryption
- Encryption that uses a public and private key pair, used for key exchange and digital signatures.
- Hashing
- A one-way function that produces a fixed-length value used to verify integrity; it cannot be reversed to recover data.
- Key management
- The secure generation, storage, distribution, rotation, backup and destruction of cryptographic keys.
- Hardware security module (HSM)
- A tamper-resistant device that generates, stores and uses cryptographic keys securely.
- Tokenization
- Replacing sensitive data with a non-sensitive substitute value, with the real data held in a secure vault.
- Public key infrastructure (PKI)
- The policies, roles and systems used to issue, manage and revoke digital certificates.
- Certificate authority (CA)
- A trusted entity that issues and digitally signs certificates binding public keys to identities.
- Registration authority (RA)
- The entity that verifies the identity of certificate applicants before the CA issues certificates.
- Digital signature
- A hash of a message encrypted with the signer's private key, providing integrity, origin authentication and non-repudiation.
- Certificate revocation list (CRL)
- A signed list, published by a CA, of certificates revoked before their expiry dates.
- Online certificate status protocol (OCSP)
- A protocol for checking the revocation status of a single certificate in real time.
- Non-repudiation
- Assurance that a party cannot credibly deny having sent or signed a message.
- Hypervisor
- Software that creates and runs virtual machines, sharing physical hardware among them.
- Shared responsibility model
- The division of security duties between cloud provider and customer, varying across IaaS, PaaS and SaaS.
- Infrastructure as a service (IaaS)
- A cloud model providing virtual compute, storage and networking, with the customer managing operating systems and above.
- Software as a service (SaaS)
- A cloud model in which the provider runs the complete application and the customer manages users, configuration and data.
- Mobile device management (MDM)
- Tools that enforce security settings, manage apps and allow remote wipe on mobile devices.
- Internet of Things (IoT)
- Network-connected devices such as sensors, cameras and controllers, often with limited built-in security.
- Complementary user entity controls
- Controls a service provider's report assumes the customer operates for the overall control objectives to be met.
- Phishing
- A deceptive message designed to trick recipients into revealing information, clicking malicious links or opening malware.
- Business email compromise (BEC)
- Fraud using spoofed or hijacked business email accounts to request payments or sensitive data.
- Social engineering
- Manipulating people into breaking security practices or revealing information.
- Ransomware
- Malware that encrypts data, and often steals it, to extort payment from the victim.
- Credential stuffing
- Using usernames and passwords leaked from one site to try to log in to other sites.
- SQL injection
- An attack that inserts malicious database commands through poorly validated input fields.
- Advanced persistent threat (APT)
- A skilled, well-resourced attacker that maintains long-term hidden access to a target network.
- Vulnerability scan
- An automated check of systems for known weaknesses such as missing patches and misconfigurations.
- Authenticated scan
- A vulnerability scan that logs in to systems, giving more complete and accurate results.
- Penetration test
- An authorized attempt to exploit weaknesses to demonstrate real-world impact.
- Rules of engagement
- The agreed terms for a security test, including scope, timing, methods, contacts and data handling.
- Black box testing
- Testing with no prior knowledge of the target environment, simulating an outside attacker.
- Red team exercise
- A realistic, often extended simulation of an adversary to test prevention, detection and response.
- Static application security testing (SAST)
- Analysis of application source code for security flaws without running the program.
- Security information and event management (SIEM)
- A system that collects, normalizes and correlates logs from many sources to detect and alert on security events.
- Correlation rule
- Logic in a SIEM that links related events across sources to identify suspicious patterns.
- Alert fatigue
- Desensitization caused by too many alerts, especially false positives, leading to real threats being missed.
- Security operations center (SOC)
- The team and function that monitors, triages and escalates security alerts.
- Security orchestration, automation and response (SOAR)
- Tools that automate and coordinate response actions using predefined playbooks.
- User and entity behavior analytics (UEBA)
- Analytics that baseline normal behavior of users and devices and flag deviations.
- Use case
- A defined threat scenario the monitoring program is designed to detect, with the data and rules needed.
- Incident response plan
- An approved document defining roles, procedures and communications for handling security incidents.
- Containment
- Actions that limit the spread and impact of an incident, such as isolating systems or disabling accounts.
- Eradication
- Removing the cause of an incident, such as malware and attacker access, and closing the exploited weakness.
- Order of volatility
- The sequence for collecting evidence from most volatile, such as memory, to least volatile, such as archives.
- Chain of custody
- Documentation of who collected, handled, transferred and stored evidence, proving it was not altered.
- Forensic image
- A bit-for-bit copy of storage media, verified by hash values, used for analysis instead of the original.
- Write blocker
- A device or software that prevents any changes to media while it is being copied or examined.
Study CISA for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CISA study planLessons, quizzes, exam simulations and hands-on labs.