StudyToCert

All certifications / CISA / Lessons

ISACA Certified Information Systems Auditor (CISA) 2024 job practice · Domain 2: Governance and management of IT

Laws, regulations and industry standards affecting the organization

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Organizations operate under a web of legal and contractual obligations: privacy and data protection laws, financial reporting rules, sector regulations for health care, banking or critical infrastructure, breach notification laws, export controls, e-discovery and records retention rules, and industry standards such as the Payment Card Industry Data Security Standard (PCI DSS). An IS auditor must understand which of these apply, because they become the criteria against which controls are judged, and non-compliance can bring fines, lawsuits, loss of licenses or loss of the right to process card payments.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISA for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISA study plan