StudyToCert

All certifications / CISA / Cheat sheet

CISA 2024 job practice cheat sheet

Every exam tip and key term from the free CISA lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Information system auditing process (18%)

Exam tips

Key terms

ITAF
ISACA's IT Audit Framework: mandatory standards, supporting guidelines, and tools and techniques for IS audit and assurance work.
Audit charter
A board- or audit committee-approved document that sets out the audit function's purpose, authority, responsibility and access rights.
Organizational independence
A reporting line for the audit function, usually to the audit committee, that lets it work without interference from the areas it audits.
Independence in appearance
The absence of circumstances that would lead a reasonable third party to doubt the auditor's objectivity.
Due professional care
Applying the skill and diligence that a prudent, competent auditor would use in the same circumstances.
Self-review threat
The risk that an auditor will not critically evaluate work they performed or designed themselves.
Code of Professional Ethics
ISACA's set of conduct principles that members and certification holders agree to follow, enforced through disciplinary procedures.
Integrated audit
An audit that combines financial, operational and IS audit work to evaluate all the controls over a process or system together.
Control self-assessment (CSA)
A technique in which process owners and staff evaluate their own controls, usually in facilitated workshops.
Forensic audit
An engagement to collect and analyze evidence about suspected fraud or crime for possible legal or disciplinary use.
Compliance audit
An audit that tests adherence to specific laws, regulations, contracts or internal policies.
Operational audit
An audit that evaluates the efficiency, effectiveness and economy of a process or function.
Chain of custody
A documented record of who collected, handled and stored evidence, and when, showing it was not altered.
Reasonable assurance
A high but not absolute level of assurance, which is the level an audit opinion provides.
Audit universe
The complete list of auditable areas in the organization, used as the starting point for risk-based planning.
Inherent risk
The risk of an error or loss before considering any controls.
Control risk
The risk that an error will not be prevented or detected in time by the organization's controls.
Detection risk
The risk that the auditor's procedures fail to detect a material error; the only part of audit risk the auditor controls.
Materiality
The significance of a weakness or error, judged by its potential effect on decisions or objectives, not only its monetary value.
Engagement scope
The boundaries of a specific audit: the systems, processes, locations and time period included.
Preventive control
A control designed to stop an error or irregularity from occurring.
Detective control
A control that identifies errors or irregularities after they have occurred.
Corrective control
A control that fixes a problem and limits its impact once it has been detected.
Compensating control
An alternative control that reduces risk to an acceptable level when the primary control cannot be implemented.
IT general control (ITGC)
A control over the IT environment, such as access or change management, that supports all applications running in it.
Application control
A control inside a specific application that ensures complete, accurate and authorized input, processing and output.
Operating effectiveness
Whether a control actually functioned as designed, consistently, throughout the period under review.
Audit program
A step-by-step list of audit procedures designed to meet the objectives of a specific engagement.
Workpapers
The documented record of audit planning, procedures, evidence and conclusions, reviewed by a senior auditor.
Engagement letter
A document that confirms the scope, objectives, timing, responsibilities and access for an audit.
Scope limitation
A restriction on the auditor's access or procedures that prevents gathering sufficient evidence.
Fieldwork
The phase of an audit in which tests are performed and evidence is gathered.
Guest auditor
A subject matter expert from another part of the organization or outside who joins an engagement to supply missing skills.
Compliance test
A test of whether a control operates as designed, such as checking approvals on a sample of changes.
Substantive test
A test of the data or transactions themselves to detect errors or misstatement.
Attribute sampling
A method that estimates the rate at which a characteristic, such as a control failure, occurs in a population.
Variable sampling
A method that estimates a monetary amount or other quantity in a population, used for substantive testing.
Discovery sampling
A form of attribute sampling designed to find at least one instance of a rare event, such as fraud.
Tolerable error rate
The maximum rate of deviation the auditor is willing to accept and still rely on the control.
Stratification
Dividing a population into subgroups with similar characteristics so each can be sampled appropriately.
Sufficient evidence
Enough evidence, in quantity and coverage, to support the audit conclusion.
Reliable evidence
Evidence whose source, method and conditions of production make it trustworthy.
Relevant evidence
Evidence that logically relates to and addresses the specific audit objective.
Reperformance
The auditor independently executing a control or calculation to confirm it produces the correct result.
Corroboration
Obtaining additional evidence to confirm information gathered through inquiry or other weaker sources.
Walkthrough
Tracing a single transaction through a process to confirm the auditor's understanding of controls.
Confirmation
Evidence obtained directly from an independent third party, such as a bank or vendor, in response to the auditor's request.
CAAT
Computer-assisted audit technique: using software to extract and analyze data or test system logic as part of an audit.
Parallel simulation
Reprocessing production data with auditor-controlled software and comparing the results with the production output.
Test data
Dummy transactions, valid and invalid, run through a program to check that it processes and rejects them correctly.
Integrated test facility (ITF)
A technique that creates fictitious entities in a live system so auditor test transactions are processed alongside real ones.
Embedded audit module
Code inside an application that selects transactions meeting audit criteria as they are processed.
Continuous auditing
Audit testing performed automatically and frequently, close to when transactions occur.
Continuous monitoring
Management's ongoing, automated oversight of controls and key indicators.
Condition
The part of a finding that states what the auditor actually observed.
Criteria
The standard, policy or expectation that the condition is measured against.
Cause
The underlying reason the condition differs from the criteria, which a lasting fix must address.
Effect
The actual or potential impact or risk that results from the condition.
Exit meeting
A meeting at the end of fieldwork where findings are discussed with management before the report is finalized.
Follow-up
Audit procedures that verify whether agreed corrective actions were implemented and effective.
External quality assessment
An independent review of the audit function's conformance with standards and its effectiveness.

Domain 2: Governance and management of IT (18%)

Exam tips

Key terms

Regulatory compliance
Meeting the requirements imposed by laws and regulations that apply to the organization.
Compliance register
A maintained list of applicable legal, regulatory and contractual requirements with owners and status.
Gap assessment
A comparison of current controls and practices against a set of requirements to identify shortfalls.
Breach notification
A legal requirement to inform regulators or affected people when certain data is compromised.
Industry standard
A requirement set developed by an industry body, such as for card payments, which may become binding through contracts.
Data residency
A requirement that certain data be stored or processed within a specific country or region.
IT governance
The leadership, structures and processes that ensure IT supports the organization's strategy and objectives.
IT steering committee
A management committee of business and IT leaders that prioritizes, approves and monitors IT investments.
IT strategy committee
A board-level committee that advises the board on the strategic direction of IT.
Business alignment
The degree to which IT plans and investments support the organization's strategic goals.
IT strategic plan
A multi-year plan describing how IT will support business goals, including priorities, investments and measures.
Shadow IT
Technology acquired or used by business units without the knowledge or approval of IT governance.
RACI chart
A matrix showing who is responsible, accountable, consulted and informed for each activity or decision.
Policy
A high-level, management-approved statement of intent and direction.
Standard
A mandatory, specific requirement that supports a policy.
Procedure
Detailed, step-by-step instructions to perform a task.
Guideline
Recommended but optional advice on how to meet a policy or standard.
Baseline
A minimum required configuration or security level for a specific platform or system.
COBIT
ISACA's framework for governance and management of enterprise information and technology.
Policy exception
A formally requested, risk-assessed and approved deviation from a policy or standard, usually time-limited.
Enterprise architecture
A structured description of business processes, information, applications and technology and how they should evolve.
Enterprise risk management (ERM)
The organization-wide process for identifying, assessing, responding to, monitoring and reporting risks to objectives.
Risk appetite
The amount and type of risk an organization is willing to pursue or retain to achieve its objectives.
Risk tolerance
The acceptable level of variation around a specific objective or risk appetite.
Residual risk
The risk remaining after controls and other responses are applied.
Risk owner
The person accountable for managing a particular risk and deciding on its response.
Risk transfer
Shifting some of the financial impact of a risk to another party, such as an insurer, while keeping accountability.
Purpose limitation
The principle that personal data is used only for the specific purposes for which it was collected.
Data minimization
Collecting and keeping only the personal data that is necessary for the stated purpose.
Storage limitation
Keeping personal data in identifiable form no longer than necessary for its purpose.
Privacy impact assessment (PIA)
An evaluation of how a new system or change affects personal data and privacy risk, done before it is implemented.
Privacy by design
Building privacy protections into systems and processes from the start, with protective settings as the default.
Pseudonymization
Replacing direct identifiers with tokens so data can be re-linked only using separately protected information.
Data protection officer (DPO)
A person responsible for overseeing an organization's privacy compliance and advising on data protection obligations.
Data owner
The business manager accountable for a data set, who decides its classification and approves access.
Data custodian
The party, often IT, that implements and maintains controls over data on the owner's behalf.
Data steward
A person responsible for the quality, definitions and proper use of data day to day.
Data classification
Assigning data to sensitivity levels that determine how it must be handled and protected.
Data inventory
A catalog of the organization's data sets, where they reside, their owners and their classification.
Data lineage
A record of where data originated and how it has been moved and transformed.
Data loss prevention (DLP)
Tools and processes that detect and block unauthorized movement of sensitive data based on its classification.
Segregation of duties
Dividing incompatible duties among different people so that no single person can commit and conceal errors or fraud.
SoD matrix
A table of roles or permissions that marks which combinations are incompatible, used to detect conflicts.
Compensating control
An alternative control that reduces risk when the ideal control, such as full segregation of duties, cannot be applied.
Job rotation
Periodically moving staff between roles, which reduces dependence on individuals and can reveal irregularities.
Mandatory vacation
Requiring staff in sensitive roles to take consecutive leave so others perform their duties and irregularities surface.
Portfolio management
Managing a set of IT investments together to maximize value and alignment within available resources.
Chargeback
A cost allocation model that bills business units for the IT services they consume.
Right-to-audit clause
A contract term allowing the customer, or its auditors, to audit the vendor's controls.
Service level agreement (SLA)
A contract section defining measurable service targets, how they are reported and the remedies if they are missed.
SOC 1
An independent report on a service organization's controls relevant to customers' internal control over financial reporting.
SOC 2 Type 2
An independent report on a service organization's controls over the trust services criteria, including testing of operating effectiveness over a period.
Complementary user entity controls
Controls that the customer must perform for the service organization's controls to be effective.
Source code escrow
An arrangement where a third party holds a vendor's source code, released to the customer if the vendor fails.
Carve-out method
A SOC reporting approach that excludes a subservice organization's controls from the report's scope.
Key performance indicator (KPI)
A measure of how well a process or activity is achieving its objective.
Key risk indicator (KRI)
A metric that signals increasing exposure to a particular risk.
Balanced scorecard
A performance tool that measures IT across business contribution, user orientation, operational excellence and future orientation perspectives.
Operational level agreement (OLA)
An agreement between internal teams that defines the support needed to meet an external service level agreement.
Capability level
A rating of how well a process is performed and managed, from incomplete to optimized.
Quality assurance
Activities that define and check processes to prevent defects, as opposed to inspecting outputs.
Maturity model
A staged model describing how processes evolve from ad hoc to optimized, used to assess and plan improvement.

Domain 3: Information systems acquisition, development and implementation (12%)

Exam tips

Key terms

Project sponsor
The senior business leader who owns the business case, funds the project and is accountable for its benefits.
Project steering committee
A group of senior stakeholders that directs the project and approves major changes to scope, budget and schedule.
Earned value
The budgeted cost of the work actually completed at a point in time.
Cost performance index (CPI)
Earned value divided by actual cost; below 1 means the project is over budget.
Critical path
The longest sequence of dependent tasks, which determines the shortest possible project duration.
Work breakdown structure (WBS)
A hierarchical decomposition of project deliverables into manageable work packages.
Scope creep
Uncontrolled growth in project scope without matching changes in budget, time or approval.
Business case
A document that justifies an investment by comparing options, costs, benefits and risks.
Feasibility study
An analysis of whether a proposed solution is technically, economically, operationally, legally and schedule-wise practical.
Total cost of ownership (TCO)
All costs of a solution over its life, including acquisition, operation, support and retirement.
Net present value (NPV)
The value today of future cash inflows minus outflows, discounted to account for the time value of money.
Payback period
The time it takes for cumulative benefits to equal the initial investment.
Request for proposal (RFP)
A formal document inviting vendors to propose solutions against stated requirements and evaluation criteria.
Sunk cost
Money already spent that cannot be recovered and should not drive future decisions.
Waterfall (SDLC)
A sequential development approach where each phase is completed and signed off before the next begins.
Product backlog
A prioritized list of features and requirements, usually written as user stories, used in agile development.
Definition of done
The agreed criteria, such as passing tests and review, that a work item must meet before it is considered complete.
DevOps
Practices that combine development and operations with automation to deliver changes quickly and reliably.
CI/CD pipeline
An automated sequence that builds, tests and releases code changes, often with gates for review and approval.
Prototyping
Building an early working model of a system to refine requirements with users.
Rapid application development (RAD)
A method that uses prototypes, reusable components and timeboxing to deliver systems quickly.
Validity check
An edit check that accepts only values that are permitted for a field, such as real dates or valid codes.
Check digit
A calculated digit appended to a number that detects transcription errors when the number is entered.
Hash total
A total of a non-financial field, such as account numbers, used to detect changes or missing items in a batch.
Control total
A total of a meaningful amount field, such as invoice value, compared before and after processing.
Run-to-run totals
Control totals carried from one processing step to the next to confirm nothing was lost or added.
Suspense file
A holding area for rejected transactions until they are corrected and resubmitted by authorized staff.
Audit trail
A chronological record of system activity showing who did what and when, supporting detection and investigation.
Unit testing
Testing individual program modules in isolation, usually by developers.
Integration testing
Testing that modules and interfaces work together and pass data correctly.
User acceptance testing (UAT)
Testing by business users to confirm the system meets their requirements before go-live.
Regression testing
Rerunning previous tests after a change to confirm existing functions still work.
Black-box testing
Testing functionality by checking outputs for given inputs without examining internal code.
Stress testing
Testing system behavior at and beyond expected peak loads to find breaking points.
Data masking
Replacing sensitive values in test data with realistic but fictitious values to protect privacy.
Configuration management
Identifying, recording and controlling the approved configuration of system components and verifying it matches what is running.
Configuration management database (CMDB)
A repository that records configuration items, their attributes and relationships.
Release management
The process of planning, packaging, approving and deploying tested changes into production.
Parallel changeover
Running the old and new systems at the same time and comparing results before switching fully.
Pilot changeover
Implementing the new system in one location or group first before rolling it out more widely.
Direct cutover
Switching from the old system to the new one at a single point in time with no parallel running.
Rollback plan
A prepared procedure to return to the previous state if a release fails.
Data conversion
Transforming and moving data from an old system's format into a new system's format.
Data mapping
Defining which field in the source system corresponds to which field in the target system, with any transformation rules.
Parallel run
Operating the old and new systems at the same time and comparing their results before relying on the new one.
Infrastructure as code (IaC)
Defining servers, networks and cloud resources in version-controlled files that tools use to build environments automatically.
Shared responsibility model
The division of security duties between a cloud provider and its customer, which varies by service model.
Post-implementation review (PIR)
A review after a system has operated for a while to assess whether it met its objectives, delivers expected benefits and has effective controls.
Benefits realization
Planning, tracking and confirming that the benefits promised in the business case are actually achieved.
Benefit owner
The business manager accountable for delivering a specific benefit after the project closes.
Lessons learned
Documented insights from a project about what worked and what did not, intended to improve future projects.
Baseline
The measured starting value of a metric, used to show how much a project changed it.

Domain 4: Information systems operations and business resilience (26%)

Exam tips

Key terms

IT asset management (ITAM)
Tracking and controlling IT assets from request and procurement through use to retirement and disposal.
Configuration management database (CMDB)
A repository of IT components and their relationships, used to support change, incident and asset management.
Software asset management (SAM)
Managing software installations and use against purchased licenses to stay compliant and avoid waste.
End of life (EOL)
The point after which a vendor no longer supports a product with fixes or security updates.
Automated discovery
Tools that scan networks and systems to find devices and software, including ones missing from the inventory.
Cryptographic erase
Sanitizing encrypted media by securely destroying the encryption key so the stored data cannot be read.
Media sanitization
Removing data from storage media so it cannot be recovered, using methods suited to the media and sensitivity.
Job scheduler
Software that runs batch jobs automatically in a defined order and time, handling dependencies between them.
Batch processing
Processing groups of transactions together at scheduled times rather than one at a time as they occur.
System interface
A connection that transfers data between two applications, in batches or in real time.
Application programming interface (API)
A defined way for one program to request data or services from another.
Sequence number
A number assigned to each transmission or record so gaps and duplicates can be detected.
Robotic process automation (RPA)
Software bots that perform repetitive tasks by interacting with applications the way a user would.
Rerun log
A record of jobs that were restarted or run again, reviewed to detect duplicate or unauthorized processing.
End-user computing (EUC)
Applications such as spreadsheets, desktop databases and low-code tools built or managed by business users rather than IT.
Shadow IT
Technology, especially cloud services, acquired or used without the knowledge or approval of the IT function.
EUC inventory
A register of end-user tools that support important processes, with owners and risk ratings.
Cloud access security broker (CASB)
A tool that discovers cloud service use and applies security policies between users and cloud providers.
Proportionate control
A control whose strength matches the risk of the process or tool it protects.
Key person dependency
Reliance on one individual who alone understands or can maintain a process or tool.
Availability
The proportion of agreed service time during which a system or service is able to perform its function.
Capacity management
Ensuring IT resources meet current and forecast demand at acceptable cost and performance.
Mean time between failures (MTBF)
The average operating time between failures of a component, a measure of reliability.
Mean time to repair (MTTR)
The average time taken to restore a component or service after a failure, a measure of maintainability.
Resilience
The ability of a service to keep operating, possibly at a reduced level, when some components fail.
Capacity plan
A document that forecasts resource demand and sets out thresholds and planned actions to meet it.
Auto-scaling
Automatically adding or removing cloud resources in response to demand, within defined limits.
Incident
An unplanned interruption or reduction in the quality of an IT service.
Problem
The unknown underlying cause of one or more incidents.
Root cause analysis
A structured investigation, using techniques such as the five whys, to find the fundamental cause of a problem.
Known error
A problem whose root cause is identified and documented, often with a workaround, but not yet permanently fixed.
Known error database (KEDB)
A repository of known errors and workarounds that helps the service desk resolve incidents faster.
Workaround
A temporary way to reduce or remove the impact of an incident without fixing its root cause.
Escalation
Passing an incident to more specialized teams (functional) or to management (hierarchical) when needed.
Change advisory board (CAB)
A group that reviews and approves or rejects significant changes to production systems.
Emergency change
An urgent change that follows an expedited path but must still be logged and reviewed and approved afterward.
Standard change
A low-risk, pre-approved, repeatable change that follows a defined procedure.
Configuration item (CI)
Any component that is managed and recorded, such as a server, application version or network device.
Configuration drift
Divergence of a system's actual settings from its approved configuration baseline.
Release management
Planning, packaging and deploying approved changes to production in a controlled way.
Patch management
Identifying, testing, prioritizing, deploying and verifying vendor updates that fix vulnerabilities and defects.
Log retention
The period for which logs must be kept, set by policy, contract or regulation.
Time synchronization
Keeping system clocks aligned, usually with NTP, so events from different systems can be correlated.
Centralized logging
Forwarding logs to a separate, protected store so they cannot be altered by the source system's administrators.
Service level agreement (SLA)
An agreement between an IT service provider and its customer that sets measurable service targets.
Operational level agreement (OLA)
An internal agreement between IT teams that supports delivery of an SLA.
Underpinning contract
A contract with an external supplier that supports the service targets in an SLA.
Service catalog
A list of the IT services offered, with their descriptions, owners and service levels.
Database management system (DBMS)
Software that stores and manages data, controlling access, integrity, concurrency and recovery.
Referential integrity
A rule that every foreign key value must match an existing primary key in the related table.
Entity integrity
A rule that every row has a unique, non-null primary key.
Normalization
Organizing tables so each fact is stored once, reducing redundancy and update anomalies.
ACID
Atomicity, consistency, isolation and durability: the properties that make database transactions reliable.
Database activity monitoring (DAM)
Tools that record and analyze database activity, alerting on unusual or unauthorized actions.
Data fix
A direct change to production data outside the normal application, which should be approved, logged and reviewed.
Business impact analysis (BIA)
An analysis that identifies critical processes, their dependencies and the impact of disruption over time.
Maximum tolerable downtime (MTD)
The longest a process can be unavailable before the impact becomes unacceptable to the organization.
Recovery time objective (RTO)
The target time within which a system or process must be restored after a disruption.
Recovery point objective (RPO)
The maximum acceptable amount of data loss, measured as time before the disruption.
Service delivery objective (SDO)
The level of service that must be achieved during the recovery period.
Criticality
The relative importance of a process or system, based on the impact of its loss.
Dependency
A resource, such as a system, supplier or facility, that a process needs in order to operate.
Single point of failure
A component whose failure alone stops the whole service.
Redundant array of independent disks (RAID)
A method of combining disks for performance, redundancy or both, with levels such as 1, 5, 6 and 10.
Incremental backup
A backup of changes since the last backup of any type; fast to create but slower to restore.
Differential backup
A backup of all changes since the last full backup; a restore needs only the full backup and the latest differential.
Immutable backup
A backup copy that cannot be modified or deleted for a defined period, protecting it from ransomware.
Fault tolerance
The ability of a system to continue operating without interruption when a component fails.
Synchronous replication
Replication in which writes are confirmed only after both sites store them, giving near-zero data loss.
Business continuity plan (BCP)
A plan for keeping critical business processes running during and after a disruption.
Disaster recovery plan (DRP)
The part of continuity planning that restores IT systems, data and infrastructure.
Hot site
A fully equipped alternate site with current data that can take over within hours.
Warm site
An alternate site with some equipment and connectivity that needs configuration and data restoration before use.
Cold site
An alternate site providing only space, power and environmental controls, with equipment to be installed.
Tabletop exercise
A discussion-based test in which the team walks through a scenario to check roles and procedures.
Parallel test
A test that brings up recovery systems and processes data at the alternate site without stopping production.
Full interruption test
A test that actually shuts down primary operations and runs from the recovery site.

Domain 5: Protection of information assets (26%)

Exam tips

Key terms

Information security policy
A high-level, management-approved statement of security objectives, scope, roles and commitment.
Standard
A mandatory, specific requirement that implements a policy, such as minimum encryption strength.
Guideline
Recommended, non-mandatory advice on good practice.
Security baseline
The minimum secure configuration required for a type of system, used to harden and assess it.
Information security management system (ISMS)
A management process, defined in ISO/IEC 27001, for managing information security risks and improving controls.
Policy exception
A formally approved, time-limited deviation from a policy or standard, with assessed risk and compensating controls.
Data owner
The business manager accountable for a data set, who decides its classification and who may access it.
Mantrap (access control vestibule)
A space with two interlocking doors that admits one authorized person at a time.
Tailgating
Following an authorized person through a secured door without authorization.
Uninterruptible power supply (UPS)
A battery-based device that supplies and conditions power during short outages and fluctuations.
Pre-action sprinkler
A sprinkler system that fills its pipes with water only after detection, then discharges when a head opens.
Dry-pipe sprinkler
A sprinkler system whose pipes hold pressurized air until a head opens, used where pipes could freeze.
Clean agent suppression
A gas-based fire suppression system that leaves no residue and does not damage electronic equipment.
Defense in depth
Layering several controls so that the failure of one does not expose the protected asset.
Least privilege
Granting users only the access they need to perform their job, and no more.
Multifactor authentication (MFA)
Authentication that requires two or more different factor types, such as knowledge, possession and inherence.
Role-based access control (RBAC)
An authorization model in which permissions are assigned to roles and users receive roles.
Privilege creep
The gradual accumulation of access rights as users change roles without losing old access.
Access recertification
A periodic review in which owners confirm or remove each user's access.
Privileged access management (PAM)
Tools and processes that control, monitor and limit administrator and other high-risk accounts.
Single sign-on (SSO)
A system that lets users authenticate once and access multiple applications, relying on a trusted identity provider.
Stateful inspection
Firewall filtering that tracks the state of connections and allows return traffic for established sessions.
Network segmentation
Dividing a network into zones with controlled traffic between them to limit the spread of compromise.
Demilitarized zone (DMZ)
A network segment that hosts internet-facing services, separated from both the internet and the internal network.
Intrusion prevention system (IPS)
An inline system that detects and blocks malicious traffic, unlike an IDS, which only alerts.
Endpoint detection and response (EDR)
Endpoint software that records behavior, detects threats and lets analysts investigate and contain devices.
Zero trust
A security model that verifies every access request based on identity and context rather than network location.
Shadowed rule
A firewall rule that never takes effect because an earlier rule matches the same traffic.
Data loss prevention (DLP)
Tools and processes that detect sensitive data and monitor or block its unauthorized movement.
Symmetric encryption
Encryption that uses the same secret key to encrypt and decrypt, fast enough for bulk data.
Asymmetric encryption
Encryption that uses a public and private key pair, used for key exchange and digital signatures.
Hashing
A one-way function that produces a fixed-length value used to verify integrity; it cannot be reversed to recover data.
Key management
The secure generation, storage, distribution, rotation, backup and destruction of cryptographic keys.
Hardware security module (HSM)
A tamper-resistant device that generates, stores and uses cryptographic keys securely.
Tokenization
Replacing sensitive data with a non-sensitive substitute value, with the real data held in a secure vault.
Public key infrastructure (PKI)
The policies, roles and systems used to issue, manage and revoke digital certificates.
Certificate authority (CA)
A trusted entity that issues and digitally signs certificates binding public keys to identities.
Registration authority (RA)
The entity that verifies the identity of certificate applicants before the CA issues certificates.
Digital signature
A hash of a message encrypted with the signer's private key, providing integrity, origin authentication and non-repudiation.
Certificate revocation list (CRL)
A signed list, published by a CA, of certificates revoked before their expiry dates.
Online certificate status protocol (OCSP)
A protocol for checking the revocation status of a single certificate in real time.
Non-repudiation
Assurance that a party cannot credibly deny having sent or signed a message.
Hypervisor
Software that creates and runs virtual machines, sharing physical hardware among them.
Shared responsibility model
The division of security duties between cloud provider and customer, varying across IaaS, PaaS and SaaS.
Infrastructure as a service (IaaS)
A cloud model providing virtual compute, storage and networking, with the customer managing operating systems and above.
Software as a service (SaaS)
A cloud model in which the provider runs the complete application and the customer manages users, configuration and data.
Mobile device management (MDM)
Tools that enforce security settings, manage apps and allow remote wipe on mobile devices.
Internet of Things (IoT)
Network-connected devices such as sensors, cameras and controllers, often with limited built-in security.
Complementary user entity controls
Controls a service provider's report assumes the customer operates for the overall control objectives to be met.
Phishing
A deceptive message designed to trick recipients into revealing information, clicking malicious links or opening malware.
Business email compromise (BEC)
Fraud using spoofed or hijacked business email accounts to request payments or sensitive data.
Social engineering
Manipulating people into breaking security practices or revealing information.
Ransomware
Malware that encrypts data, and often steals it, to extort payment from the victim.
Credential stuffing
Using usernames and passwords leaked from one site to try to log in to other sites.
SQL injection
An attack that inserts malicious database commands through poorly validated input fields.
Advanced persistent threat (APT)
A skilled, well-resourced attacker that maintains long-term hidden access to a target network.
Vulnerability scan
An automated check of systems for known weaknesses such as missing patches and misconfigurations.
Authenticated scan
A vulnerability scan that logs in to systems, giving more complete and accurate results.
Penetration test
An authorized attempt to exploit weaknesses to demonstrate real-world impact.
Rules of engagement
The agreed terms for a security test, including scope, timing, methods, contacts and data handling.
Black box testing
Testing with no prior knowledge of the target environment, simulating an outside attacker.
Red team exercise
A realistic, often extended simulation of an adversary to test prevention, detection and response.
Static application security testing (SAST)
Analysis of application source code for security flaws without running the program.
Security information and event management (SIEM)
A system that collects, normalizes and correlates logs from many sources to detect and alert on security events.
Correlation rule
Logic in a SIEM that links related events across sources to identify suspicious patterns.
Alert fatigue
Desensitization caused by too many alerts, especially false positives, leading to real threats being missed.
Security operations center (SOC)
The team and function that monitors, triages and escalates security alerts.
Security orchestration, automation and response (SOAR)
Tools that automate and coordinate response actions using predefined playbooks.
User and entity behavior analytics (UEBA)
Analytics that baseline normal behavior of users and devices and flag deviations.
Use case
A defined threat scenario the monitoring program is designed to detect, with the data and rules needed.
Incident response plan
An approved document defining roles, procedures and communications for handling security incidents.
Containment
Actions that limit the spread and impact of an incident, such as isolating systems or disabling accounts.
Eradication
Removing the cause of an incident, such as malware and attacker access, and closing the exploited weakness.
Order of volatility
The sequence for collecting evidence from most volatile, such as memory, to least volatile, such as archives.
Chain of custody
Documentation of who collected, handled, transferred and stored evidence, proving it was not altered.
Forensic image
A bit-for-bit copy of storage media, verified by hash values, used for analysis instead of the original.
Write blocker
A device or software that prevents any changes to media while it is being copied or examined.
Study CISA for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CISA study plan