CISA IT Audit Standards and Frameworks 1 — Questions and Answers
Question 1: What does the acronym COBIT stand for?
- Control Objectives for Business and Related Technology (Correct answer)
- Certified Objectives for Business and Information Technology
- Control Outcomes for Business and IT
- Controls and Objectives for Business and Information Technology
Correct answer: Control Objectives for Business and Related Technology
COBIT stands for Control Objectives for Business and Related Technology, the IT governance and management framework developed by ISACA.
Question 2: ISO 27001 is an international standard that primarily addresses which of the following?
- IT service management requirements
- Information security management systems (ISMS) (Correct answer)
- IT governance principles for boards
- Business continuity planning
Correct answer: Information security management systems (ISMS)
ISO 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
Question 3: The COSO Internal Control — Integrated Framework is primarily designed to help organizations with which concern?
- Delivering IT services efficiently
- Internal control and enterprise risk management (Correct answer)
- Network security architecture
- Agile software development practices
Correct answer: Internal control and enterprise risk management
COSO is a widely adopted framework for designing, implementing, and evaluating internal control and enterprise risk management across an organization.
Question 4: Which framework is specifically designed for IT service management best practices?
- COBIT
- COSO
- ITIL (Correct answer)
- ISO 27001
Correct answer: ITIL
ITIL (Information Technology Infrastructure Library) is the globally recognized framework of best practices for IT service management.
Question 5: COBIT 2019 organizes governance and management objectives into how many domains?
- 3
- 4
- 5 (Correct answer)
- 6
Correct answer: 5
COBIT 2019 defines five domains: EDM (governance) and APO, BAI, DSS, MEA (management), for a total of five domains.
Question 6: Which ISO standard specifically addresses IT governance for organizations?
- ISO 27001
- ISO 31000
- ISO 38500 (Correct answer)
- ISO 20000
Correct answer: ISO 38500
ISO 38500 provides principles for the governance of IT, guiding board members and senior managers in evaluating, directing, and monitoring IT use.
Question 7: ISACA's IS Audit and Assurance Standards are organized into which three primary categories?
- Planning, Execution, Reporting
- Standards, Guidelines, and Tools and Techniques (Correct answer)
- Policies, Procedures, and Controls
- Auditing, Monitoring, and Assurance
Correct answer: Standards, Guidelines, and Tools and Techniques
ISACA organizes its IS audit and assurance publications into Standards (mandatory), Guidelines (guidance), and Tools and Techniques (practical assistance).
What does the acronym COBIT stand for?