StudyToCert

All certifications / CISA / Lessons

ISACA Certified Information Systems Auditor (CISA) 2024 job practice · Domain 1: Information system auditing process

Types of controls: preventive, detective, corrective, compensating; general vs application controls

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

A control is any policy, procedure, practice or technical mechanism that management puts in place to give reasonable assurance that objectives will be met and that risks stay within acceptable limits. Auditors classify controls so they can judge whether the mix is sensible and decide how to test each one. The same control can be described in several ways at once: by its function, its scope and whether it is manual or automated.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISA for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISA study plan